When installing a policy package, objects that are referenced in the policy will be installed to the target device. Default or per-device mapping must exist or the installation will fail.
Some objects that are not directly referenced in the policy will also be installed to the target device, such as FSSO polling objects, address and profile groups, and CA certificates.
Some objects that are not referenced will be removed from the FortiGate. This may be particularly noticeable when installing a policy package for the first time after adding a device to FortiManager.
If you anticipate needing those objects in the future, make sure those objects are present in Policy & Objects before proceeding with the installation. To ensure that those objects are present in Policy & Objects you can use the Add ALL Objects option when importing a policy.
Policies within a policy package can be configured to install only on specified target devices. See Install policies only to specific devices.
To install a policy package to a target device:
- Ensure you are in the ADOM that contains the policy package.
- Go to Policy & Objects > Policy Packages.
- Select a policy package and from the Install menu or right-click menu select Install Wizard. The Install Wizard opens.
- Follow the steps in the install wizard to install the policy package. You can select to install policy package and device settings or install the interface policy only.
For more information on the install wizard, see Using the Install Wizard to install policy packages and device settings. For more information on editing the installation targets, see Policy package installation targets.