Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
luca1994
Contributor

Unable to create policy package from Fortimanager (button is grey-out)

Hello Team,

 

I connected an already configured fortigate cluster to a Fortimanager. Now I wanted to try to create a policy from the Fortimanager and push it to the firewall. Can you point me to the correct procedure?
To do this I saw that you have to create a policy package but I have the grey button and I can't click it.

I am logging into the FortiManager as an admin user (so I am ruling out permissions problems).

I point out that on the same adom (root) as Fortimanager there is already another pair of fortigates which already have a policy package assigned.

 

Please feel free to ask for more details.
I thank you in advance for the support

BR

 

1 Solution
kaman
Staff
Staff

Hi luca1994,

Go to System Settings > Admin Profiles, identify the profile assigned to the system admin, enable 'Read-Write' for 'Add/Delete/Edit Devices/Groups' and 'Lock/Unlock ADOM', then verify the behaviour.

If you have found a solution, please like and accept it to make it easily accessible to others.


Regards,
Aman

View solution in original post

3 REPLIES 3
kaman
Staff
Staff

Hi luca1994,

Please note the firewall policy option is visible only if the NGFW Mode is selected as Profile-based in the policy package.

Kindly refer to the documents below for more information:

https://docs.fortinet.com/document/fortimanager/7.6.0/administration-guide/663598/create-a-new-firew...

https://community.fortinet.com/t5/FortiManager/Technical-Tip-FortiManager-policy-package-installatio...


Regards,
Aman

luca1994

Hello @kaman,

NGFW Mode is already selected as Profile-based.

 

FortiManager version --> 7.2.10

FortiOS versione --> 7.2.10

 

I currently have a fortigate 6.4 connected to FortiManagere with a policy package assigned but even here I have the “new” button disabled. I see that the “add device” button from FortiManager is also disabled.

 

Thanks

BR

 

kaman
Staff
Staff

Hi luca1994,

Go to System Settings > Admin Profiles, identify the profile assigned to the system admin, enable 'Read-Write' for 'Add/Delete/Edit Devices/Groups' and 'Lock/Unlock ADOM', then verify the behaviour.

If you have found a solution, please like and accept it to make it easily accessible to others.


Regards,
Aman

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors