config firewall address6
Configure IPv6 firewall addresses.
config firewall address6
Description: Configure IPv6 firewall addresses.
edit <name>
config addr-8021x
Description: 802.1X address. Read-only.
edit <interface>
set acct-user {string}
set ip6 {ipv6-address}
set mac {string}
set vlan-id {integer}
next
end
set cache-ttl {integer}
set color {integer}
set comment {var-string}
set country {string}
set custom-tags <name1>, <name2>, ...
set display-with [all-tags|first-tag-only|...]
set end-ip {ipv6-address}
set epg-name {string}
set fabric-force-sync [enable|disable]
set fabric-object [enable|disable]
set fabric-object-source [member|local|...]
set filter {var-string}
set fqdn {string}
set host {ipv6-address}
set host-type [any|specific]
set ip6 {ipv6-network}
config list
Description: IP address list.
edit <ip>
next
end
set macaddr <macaddr1>, <macaddr2>, ...
set obj-id {var-string}
set obj-tag {string}
set obsolete {integer}
set passive-fqdn-learning [disable|enable]
set route-tag {integer}
set sdn {string}
set sdn-addr-type [private|public|...]
set sdn-tag {string}
set start-ip {ipv6-address}
set sub-type [sdn|ems-tag|...]
config subnet-segment
Description: IPv6 subnet segments.
edit <name>
set type [any|specific]
set value {string}
next
end
set tag-detection-level {string}
set tag-type {string}
config tagging
Description: Config object tagging.
edit <name>
set category {string}
set tags <name1>, <name2>, ...
next
end
set template {string}
set tenant {string}
set type [ipprefix|iprange|...]
set uuid {uuid}
set wildcard {ipv6-wildcard}
next
end
config firewall address6
|
Parameter |
Description |
Type |
Size |
Default |
||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
cache-ttl |
Minimal TTL of individual IPv6 addresses in FQDN cache. |
integer |
Minimum value: 0 Maximum value: 86400 |
0 |
||||||||||||||||||||
|
color |
Integer value to determine the color of the icon in the GUI (range 1 to 32, default = 0, which sets the value to 1). |
integer |
Minimum value: 0 Maximum value: 32 |
0 |
||||||||||||||||||||
|
comment |
Comment. |
var-string |
Maximum length: 255 |
|
||||||||||||||||||||
|
country |
IPv6 addresses associated to a specific country. |
string |
Maximum length: 2 |
|
||||||||||||||||||||
|
custom-tags |
Custom tags. Names of custom tags used with this address. |
string |
Maximum length: 35 |
|
||||||||||||||||||||
|
display-with * |
Display object with first tag, all tags, or just the icon. |
option |
- |
all-tags |
||||||||||||||||||||
|
|
|
|||||||||||||||||||||||
|
end-ip |
Final IP address (inclusive) in the range for the address (format: xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx). |
ipv6-address |
Not Specified |
:: |
||||||||||||||||||||
|
epg-name |
Endpoint group name. |
string |
Maximum length: 255 |
|
||||||||||||||||||||
|
fabric-force-sync * |
Enable/disable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices. Configuration conflict check is skipped. |
option |
- |
disable |
||||||||||||||||||||
|
|
|
|||||||||||||||||||||||
|
fabric-object |
Security Fabric global object setting. |
option |
- |
disable |
||||||||||||||||||||
|
|
|
|||||||||||||||||||||||
|
fabric-object-source * |
Source of truth for fabric object. |
option |
- |
root |
||||||||||||||||||||
|
|
|
|||||||||||||||||||||||
|
filter |
Match criteria filter. |
var-string |
Maximum length: 2047 |
|
||||||||||||||||||||
|
fqdn |
Fully qualified domain name. |
string |
Maximum length: 255 |
|
||||||||||||||||||||
|
host |
Host Address. |
ipv6-address |
Not Specified |
:: |
||||||||||||||||||||
|
host-type |
Host type. |
option |
- |
any |
||||||||||||||||||||
|
|
|
|||||||||||||||||||||||
|
ip6 |
IPv6 address prefix (format: xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx/xxx). |
ipv6-network |
Not Specified |
::/0 |
||||||||||||||||||||
|
macaddr |
Multiple MAC address ranges. MAC address ranges <start>[-<end>] separated by space. |
string |
Maximum length: 127 |
|
||||||||||||||||||||
|
name |
Address name. |
string |
Maximum length: 79 |
|
||||||||||||||||||||
|
obj-id |
Object ID for NSX. |
var-string |
Maximum length: 255 |
|
||||||||||||||||||||
|
obj-tag * |
Tag of dynamic address object. |
string |
Maximum length: 255 |
|
||||||||||||||||||||
|
obsolete * |
Indicates whether the address can be used. Read-only. |
integer |
Minimum value: 0 Maximum value: 4294967295 |
0 |
||||||||||||||||||||
|
passive-fqdn-learning |
Enable/disable passive learning of FQDNs. When enabled, the FortiGate learns, trusts, and saves FQDNs from endpoint DNS queries (default = enable). |
option |
- |
enable |
||||||||||||||||||||
|
|
|
|||||||||||||||||||||||
|
route-tag |
route-tag address. |
integer |
Minimum value: 1 Maximum value: 4294967295 |
0 |
||||||||||||||||||||
|
sdn |
SDN. |
string |
Maximum length: 35 |
|
||||||||||||||||||||
|
sdn-addr-type |
Type of addresses to collect. |
option |
- |
private |
||||||||||||||||||||
|
|
|
|||||||||||||||||||||||
|
sdn-tag |
SDN Tag. |
string |
Maximum length: 15 |
|
||||||||||||||||||||
|
start-ip |
First IP address (inclusive) in the range for the address (format: xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx:xxxx). |
ipv6-address |
Not Specified |
:: |
||||||||||||||||||||
|
sub-type * |
Sub-type of address. |
option |
- |
sdn |
||||||||||||||||||||
|
|
|
|||||||||||||||||||||||
|
tag-detection-level * |
Tag detection level of dynamic address object. |
string |
Maximum length: 15 |
|
||||||||||||||||||||
|
tag-type * |
Tag type of dynamic address object. |
string |
Maximum length: 63 |
|
||||||||||||||||||||
|
template |
IPv6 address template. |
string |
Maximum length: 63 |
|
||||||||||||||||||||
|
tenant |
Tenant. |
string |
Maximum length: 35 |
|
||||||||||||||||||||
|
type |
Type of IPv6 address object (default = ipprefix). |
option |
- |
ipprefix |
||||||||||||||||||||
|
|
|
|||||||||||||||||||||||
|
uuid |
Universally Unique Identifier (UUID; automatically assigned but can be manually reset). |
uuid |
Not Specified |
00000000-0000-0000-0000-000000000000 |
||||||||||||||||||||
|
wildcard |
IPv6 address and wildcard netmask. |
ipv6-wildcard |
Not Specified |
:: :: |
||||||||||||||||||||
* This parameter may not exist in some models.
config addr-8021x
|
Parameter |
Description |
Type |
Size |
Default |
|---|---|---|---|---|
|
acct-user |
Account user name. Read-only. |
string |
Maximum length: 64 |
|
|
interface |
Interface name. Read-only. |
string |
Maximum length: 15 |
|
|
ip6 |
IPv6 address. Read-only. |
ipv6-address |
Not Specified |
:: |
|
mac |
MAC address. Read-only. |
string |
Maximum length: 127 |
|
|
vlan-id |
VLAN ID. Read-only. |
integer |
Minimum value: 0 Maximum value: 4294967295 |
0 |
config list
|
Parameter |
Description |
Type |
Size |
Default |
|---|---|---|---|---|
|
ip |
IP. |
string |
Maximum length: 89 |
|
config subnet-segment
|
Parameter |
Description |
Type |
Size |
Default |
||||||
|---|---|---|---|---|---|---|---|---|---|---|
|
name |
Name. |
string |
Maximum length: 63 |
|
||||||
|
type |
Subnet segment type. |
option |
- |
any |
||||||
|
|
|
|||||||||
|
value |
Subnet segment value. |
string |
Maximum length: 35 |
|
||||||
config tagging
|
Parameter |
Description |
Type |
Size |
Default |
|---|---|---|---|---|
|
category |
Tag category. |
string |
Maximum length: 63 |
|
|
name |
Tagging entry name. |
string |
Maximum length: 63 |
|
|
tags |
Tags. Tag name. |
string |
Maximum length: 79 |
|