Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Tamiltk
New Contributor II

Object creation in Fortimanager

Recently, I have faced a challenge in creating the address objects in the Fortigate 2201E as the limitation is over 65000 firewall address objects. Since we are using multiple VDOMs the address object resource got exhausted.  

The object creations are mainly contributed by the IOC blocks at the firewall itself. 

Now we are left with the option of having the IOC blocks via external threat feed. But I would like to know if the Fortimanager integration would help in holding the address objects at the Fortimanager itself and cached at Fortigate, such a watch the objects wouldn't consume the fortigate resources.

Kindly let me know the feasibility of the same.

2 REPLIES 2
AEK
SuperUser
SuperUser

The external thread feed is a good choice.

Also using FortiGuard bad IP addresses DB may be the best way (if this is what you need).

You can find them under: Internet Service Database > IP Reputation Database.

You can use them in your firewall rules as source or destination.

AEK
AEK
AlexC-FTNT
Staff
Staff

Fortimanager only pushes the config changes and keeps track of them on Fortigate (in general terms).
If the objects are not on FortiGate, the config is not applied. Creating IOC blocks on FortiGate as address objects is not a good practice, as you have noticed, and external threat feeds is the way to go.


- Toss a 'Like' to your fixxer, oh Valley of Plenty! and chose the solution, too00oo -
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors