Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Mustafa_Kamel
New Contributor

Enable Application Control Profile

Hello everyone,

I need to enable application control profile on all my policies, how can i do this in one step?

 

2 Solutions
neonbit
Valued Contributor

There's no way to enable it in one step. To make it easy you can just drag/drop the application from one policy to all the others.

View solution in original post

Sidewaysguy
New Contributor III

Without touching all of the policies you want to affect individually, my only suggestion would be to back up the config, add the profile to the policies that need it and then restore the config.  The issue here is that you'd end up with down time. 

 

How many policies are you wanting to edit?  And which firmware are you using? 

 

I would have to have a massive amount of policies to warrant an outage for something like this that can be changed from the main policy GUI.  It may take a few minutes but better than an outage.

View solution in original post

4 REPLIES 4
neonbit
Valued Contributor

There's no way to enable it in one step. To make it easy you can just drag/drop the application from one policy to all the others.

Sidewaysguy
New Contributor III

Without touching all of the policies you want to affect individually, my only suggestion would be to back up the config, add the profile to the policies that need it and then restore the config.  The issue here is that you'd end up with down time. 

 

How many policies are you wanting to edit?  And which firmware are you using? 

 

I would have to have a massive amount of policies to warrant an outage for something like this that can be changed from the main policy GUI.  It may take a few minutes but better than an outage.

Mustafa_Kamel

I have many policies, it may be up to 7500 policy

Firmware : 5.2.

 

but i will enable application control on all policies in my company on all fortigate firewalls, some of this firewalls include firmware version 5.4, others include 5.2  and number of policies on all firewalls may be up to 15000 policy

 

so i need a fast action to do this without any down time and more fast

Sidewaysguy

Hey Mustafa,

 

That certainly is a lot of policies.  How many Fortigates do you have to deploy and is it the same security profile that needs to be created and deployed?  Is there an existing application security profile that is already being used and just needs to be modified?

 

So this is where it may be good to look at FortiManager to manage your fleet of Fortigates as my understanding is that you should be able to deploy something like this through central management.

 

Another thought here would be to have this scripted to both create or modify the security profile and then to add it to the appropriate policies.  This is not my forte but it is something that others can comment on. 

Labels
Top Kudoed Authors