Helpful ReplyHot!FortiManager: multiple global policy or policy package possible?

Author
jfcelda
New Member
  • Total Posts : 9
  • Scores: 0
  • Reward points: 0
  • Joined: 2014/11/24 03:49:14
  • Status: offline
2015/02/04 12:28:15 (permalink) 5.2
0

FortiManager: multiple global policy or policy package possible?

Hello,
 
I have to deploy a fortimanager and i want to know if it's possible to have multiple global policy or policy package on one device. Several devices ( fortigate) have a lot of policies in common, and I need 2 or 3 Global policies.
 
Thanks,
 
JF
#1
scao_FTNT
optimizzz
  • Total Posts : 478
  • Scores: 25
  • Reward points: 0
  • Joined: 2012/08/27 11:39:44
  • Status: offline
Re: FortiManager: multiple global policy or policy package possible? 2015/02/04 12:50:40 (permalink)
0
Hi, JF:
 
For FMG policy package, we have "install on" function for each policy, you can enable this column display in column right click menu list and then after "install on" displayed in policy page, right click, you can add a target device (from package installation target) for that specific policy, then that policy will be only installed for that device. By default, policy is installed to all package installation target devices.
 
Hope this can help for your case
 
Thanks
 
Simon
#2
jfcelda
New Member
  • Total Posts : 9
  • Scores: 0
  • Reward points: 0
  • Joined: 2014/11/24 03:49:14
  • Status: offline
Re: FortiManager: multiple global policy or policy package possible? 2015/02/05 01:39:47 (permalink)
0
Thank you,
 
It helps me.
 
JF
#3
Jad
New Member
  • Total Posts : 1
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/10/10 01:54:50
  • Status: offline
Re: FortiManager: multiple global policy or policy package possible? 2018/10/10 01:58:23 (permalink)
0
 
Hello,
 
I have the same issue, but in an other way.
 
I have multiple Fortigates, and one of them is listed on multiple Installation Target liste on multiple Policy package that are present in the FMG.
 
I would to know what is the order of these policies in that destination fortigate ?
 
How to determine the order from multiple policy package on th FMG to the same fortigate ?
 
Thanks & regards.
#4
chall_FTNT
skyhigh
  • Total Posts : 275
  • Scores: 24
  • Reward points: 0
  • Joined: 2003/11/28 16:19:30
  • Status: offline
Re: FortiManager: multiple global policy or policy package possible? 2018/10/10 08:05:06 (permalink) ☄ Helpfulby brazz_FTNT 2018/10/10 08:22:32
0
Jad,
When a policy package is installed, the FortiManager's task is to ensure that the resulting policies on FortiGate exactly match what is outlined in that package.  In other words, packages are not additive.
 
It is dangerous to have a FortiGate as an installation target for more than 1 policy package at a time because of the potential for human error in installing the wrong policy package (though FortiManager does give a warning if an admin user tries to push a policy package different than the one previously pushed).
 
It is for this reason that the FortiManager Best Practices Guide states:
"Each managed device should only have one policy package associated with it. This will help to ensure that the
wrong policy package is not mistakingly installed to a FortiGate."
post edited by chall_FTNT - 2018/10/10 08:07:28
#5
Jump to:
© 2018 APG vNext Commercial Version 5.5