Hi All,
With FGT 5.6.5 a security policy that includes a custom group (which includes custom device objects) is not matching to the last custom device I added to the custom group. When I add that same custom device to the same security policy directly along with the custom group it correctly matches to the device.
I thought I had seen something about not matching some items in custom groups a while back, but I haven't been able to find the mention of it in the forum or release notes. Anybody else seen anything similar to this?
Figured out what was causing this, which looks like a minor bug. The particular device in the custom group had had an additional MAC address (dual NIC) added to its definition after the device was already part of the custom group. This caused the custom group to automatically update itself to include both the device AND the device restricted to the (unused) other NIC. It looks like this somehow overrode the device entry in the custom group that referred to both NICs and thus didn't match. Removing the entry with the single NIC fixed it.
User | Count |
---|---|
2559 | |
1357 | |
795 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.