the format/syntax for creating an address object on FortiGate (5.x and 6.x) is
Name:
Subnet/IP range:
Do you put the IP in the name?
If not then would the "Subnet/IP range:" be the place to put the actual IP? and if so would the following be correct syntax ?
192.168.10.10/32
or
192.168.10.10 255.255.255.255
Thanks in advance
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
The name is just for your reference.
Subnet can be either cidr or full mask:
192.168.10.10/32 192.168.10.10/255.255.255.255
Or, an IP Range:
192.168.10.10-192.168.10.40
The name is just for your reference.
Subnet can be either cidr or full mask:
192.168.10.10/32 192.168.10.10/255.255.255.255
Or, an IP Range:
192.168.10.10-192.168.10.40
Looks like ive been doing it wrong the whole time....................lots fo work to do :) lol
BTW, name is not only for human reading, but other part like FW policies refer to it. "set comment <comments>" is only for human reference.
Yap, you can use an address object in a static route...so choose wisely.
I use hostnames for hosts (/32), "net-XXX" for subnets, "net-<city>" for VPN remote subnets etc. Just as examples.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.