-
Notifications
You must be signed in to change notification settings - Fork 16
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
global-label create new section each time a rule is created #83
Comments
Hi @DenisPerricone, Thanks for raising this issue. It is really weird. For example, "global-label" for policy 26 and 24 is Thanks. |
Hi, thanks for your fast answer. Unfortunately i've already checked if there are some space or hidden characters but it's absoluteli the same. I tried to pass the label via var (survey text box) or place "Sezione 1" directly in module. Unfortunately we are in production and eventually upgrade of collection doesn't is our case. As you know, there is a way (maybe sole other module/param) i can use to create a rule or to move a rule in a specific section? fmgr_pkg_firewall_policy_sectionvalue module, if understood well, produce the same issue |
Hi @DenisPerricone, I can reproduce this now. You can directly change the section value of one policy by changing the parameter "global-label", yet since the policies are in the order of creation time by default, the two policies with the same "global-label" may not be classified into one section in the GUI if there are other policies with different "global-label" between them. One way is to use
Please note, we use policy id in Thanks, |
So it's a fortimanager limit and we have to move policy ony by one and by id. Okay clear, thank you. It's a little bit hard to manage for end user because he have to know each policy ID or open FM UI, but if is not possible to add a policy on a specific section i think is the only one way. Thank you |
Further update: I asked the FMG development team. FMG can't change the display order via "global-label" because the order matters (different policy order may result in different routing behavior). Therefore, best practice is to declare policies with the same "global label" consecutively. And this is just the display issue. Even if you have two sections with the same name "Sezione 1", the "gloabl-label" values for these policies under the "Sezione 1" sections are still correct. Thanks, |
Thank you so much, you were really kind and clear. I'll do not esitate to write you if my client will be any questions or clarification. |
Hi! I've an issue with global-label parameter of fmgr_pkg_firewall_policy
When i try to create a firewall policy passing the global-label parameter, a new section is create, even if it is alteady exist.
My expectation is that if a section already exist, the module crate the rule in that section
Consider also that in fortimanager UI is not possible to have two equals section, but via module it is.
Our scope is to create N policies in predeterminated section and then install the package.
As you can see in the image below, the result is a duplicate of section named "Sezione 1"
Thanks in advance
The text was updated successfully, but these errors were encountered: