Hello,
Occasionally I'm doing changes directly on a FG that is managed from FMG and the FG goes out of sync. What is the correct process to re-sync the FG in such case?
Thanks
Andreas
Ideally you wouldn't make any changes directly on a FGT that is managed by FMG. However you can make device-level setting changes (interfaces, SNMP settings, etc) w/o impacting the sync status in FMG - BUT - you need to make sure that the policy package is in sync beforehand. If the PP is out of sync, and you make device changes locally, FMG won't auto-sync those device changes from FGT.
To re-sync settings, the safest way is to redo those changes on the FMG side and do a re-install to clear the change flag.
You can do a re-import of the policy package but there can be complications with that, so I would avoid doing that unless there is no other option.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.