Fortinet white logo
Fortinet white logo

CLI Reference

config virtual-patch profile

config virtual-patch profile

Configure virtual-patch profile.

config virtual-patch profile
    Description: Configure virtual-patch profile.
    edit <name>
        set action [pass|block]
        set comment {var-string}
        config exemption
            Description: Exempt devices or rules.
            edit <id>
                set device <mac1>, <mac2>, ...
                set rule <id1>, <id2>, ...
                set status [enable|disable]
            next
        end
        set fabric-force-sync [enable|disable]
        set fabric-object [enable|disable]
        set fabric-object-source [member|local|...]
        set log [enable|disable]
        set severity {option1}, {option2}, ...
        set uuid {uuid}
    next
end

config virtual-patch profile

Parameter

Description

Type

Size

Default

action

Action (pass/block).

option

-

block

Option

Description

pass

Allows session that match the profile.

block

Blocks sessions that match the profile.

comment

Comment.

var-string

Maximum length: 255

fabric-force-sync *

Enable/disable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices. Configuration conflict check is skipped.

option

-

disable

Option

Description

enable

Enable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices.

disable

Disable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices.

fabric-object *

Security Fabric global object setting.

option

-

disable

Option

Description

enable

Object is set as a security fabric-wide global object.

disable

Object is local to this security fabric member.

fabric-object-source *

Source of truth for fabric object.

option

-

root

Option

Description

member

Source of truth for this object is a non-root member of fabric.

local

Source of truth for this object is this security fabric member.

root

Source of truth for this object is the root of the fabric.

log

Enable/disable logging of detection.

option

-

enable

Option

Description

enable

Enable logging.

disable

Disable logging.

name

Profile name.

string

Maximum length: 47

severity

Relative severity of the signature (low, medium, high, critical).

option

-

info low medium high critical

Option

Description

info

info

low

low

medium

medium

high

high

critical

critical

uuid *

Universally Unique Identifier (UUID; automatically assigned but can be manually reset).

uuid

Not Specified

00000000-0000-0000-0000-000000000000

* This parameter may not exist in some models.

config exemption

Parameter

Description

Type

Size

Default

device <mac>

Device MAC addresses.

Device MAC address.

mac-address

Not Specified

id

IDs.

integer

Minimum value: 0 Maximum value: 4294967295

0

rule <id>

Patch signature rule IDs.

Rule IDs.

integer

Minimum value: 0 Maximum value: 4294967295

status

Enable/disable exemption.

option

-

enable

Option

Description

enable

Enable exemption.

disable

Disable exemption.

config virtual-patch profile

config virtual-patch profile

Configure virtual-patch profile.

config virtual-patch profile
    Description: Configure virtual-patch profile.
    edit <name>
        set action [pass|block]
        set comment {var-string}
        config exemption
            Description: Exempt devices or rules.
            edit <id>
                set device <mac1>, <mac2>, ...
                set rule <id1>, <id2>, ...
                set status [enable|disable]
            next
        end
        set fabric-force-sync [enable|disable]
        set fabric-object [enable|disable]
        set fabric-object-source [member|local|...]
        set log [enable|disable]
        set severity {option1}, {option2}, ...
        set uuid {uuid}
    next
end

config virtual-patch profile

Parameter

Description

Type

Size

Default

action

Action (pass/block).

option

-

block

Option

Description

pass

Allows session that match the profile.

block

Blocks sessions that match the profile.

comment

Comment.

var-string

Maximum length: 255

fabric-force-sync *

Enable/disable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices. Configuration conflict check is skipped.

option

-

disable

Option

Description

enable

Enable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices.

disable

Disable forced synchronization of configuration objects from the root FortiGate unit to the downstream devices.

fabric-object *

Security Fabric global object setting.

option

-

disable

Option

Description

enable

Object is set as a security fabric-wide global object.

disable

Object is local to this security fabric member.

fabric-object-source *

Source of truth for fabric object.

option

-

root

Option

Description

member

Source of truth for this object is a non-root member of fabric.

local

Source of truth for this object is this security fabric member.

root

Source of truth for this object is the root of the fabric.

log

Enable/disable logging of detection.

option

-

enable

Option

Description

enable

Enable logging.

disable

Disable logging.

name

Profile name.

string

Maximum length: 47

severity

Relative severity of the signature (low, medium, high, critical).

option

-

info low medium high critical

Option

Description

info

info

low

low

medium

medium

high

high

critical

critical

uuid *

Universally Unique Identifier (UUID; automatically assigned but can be manually reset).

uuid

Not Specified

00000000-0000-0000-0000-000000000000

* This parameter may not exist in some models.

config exemption

Parameter

Description

Type

Size

Default

device <mac>

Device MAC addresses.

Device MAC address.

mac-address

Not Specified

id

IDs.

integer

Minimum value: 0 Maximum value: 4294967295

0

rule <id>

Patch signature rule IDs.

Rule IDs.

integer

Minimum value: 0 Maximum value: 4294967295

status

Enable/disable exemption.

option

-

enable

Option

Description

enable

Enable exemption.

disable

Disable exemption.