Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
marionnaud
New Contributor

Two policy packages linked to same device

I took over an infrastructure from someone and it is a little bit messy. Before I make big changes I have a question.

 

Simplified environment to explain it: I have here a device group with one firewall in it. At the same time I have two policy packages. One has as the installation target the firewall itself and the other one has as the installation target the group.

 

What happens now on the firewall with the rules/policies? Are they merged together? Or is only one applied.

3 REPLIES 3
suguru26
New Contributor

The only way I know of is to associate multiple fortigates to the same policy package. You can build a policy structure where you have generic policies and then build specific policies using the "install to" field in the FMG. Extra bonus points for using sections so that all policies for a unique firewall is placed inside that section, making navigation easier.

https://19216801.onl/ https://routerlogin.uno/
marionnaud

This was not my question. I need to know how the current infrastructure behaves. Not how I should do it in the future. But thanks anyway.

asrour
Staff
Staff

- Device manager -> Device & Groups -> Managed Fortigate, you will see which policy package is installed on the Fortigate.

- keep the installation target in Policy Packages, will allow you to install the wrong policy package

A Srour
Labels
Top Kudoed Authors