Monday, April 7, 2014

Running Script Against FortiManager's Policy Package

A CLI script can be applied to the Policy Package’s Object as well as Policy Package’s Policy.    

Use the CLI commands as if you are working with the device locally, but if you have VDOM in place, just remove that part.

Instead of using

config vdom
edit “VDOM1”
…list of command…

Simply remove the VDOM reference, and leave the rest of the command.

On the script page, just use “Advanced - Override Script Target” and change the Target to Run on “Policy Package, ADOM Database or Global Policy”.