Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
austinmas
New Contributor

Tool or method to combine redundant polices

Hi Guys,

 

We have a couple of firewalls on which the policy count has exceeded 20k. Could someone please let me know if they know of a tool or a method to combine these policies. I tried to check if Forticonverter could be used but it doesn't have an option to import a Fortigate configuration. 

Thanks

 

 

1 REPLY 1
emnoc
Esteemed Contributor III

1st look for policies that has no "hits". These are signs of duplicate, or poorly written, or not required

 

Next, check the address book for duplication in hosts. These can be eliminated or corrected thru policies and address-groups

 

Ken Felix

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors