Fortinet black logo

Administration Guide

Creating object configurations

Creating object configurations

You can create new object configurations before including them in policy packages. Alternatively, you can also create policy packages using existing object configurations.

To create objects in Global Database:
  1. Change the ADOM to Global Database.
  2. Go to Policy & Objects, and select your object type from the tree menu.
  3. Click Create New to create new objects.
  4. Click OK after creating the objects.
  5. (Optional) Additional object configuration options can be enabled in Tools > Feature Visibility.
FortiGate global objects

FortiManager supports FortiGate global objects. FortiGate global objects are identified with the prefix “g-“.

When a FortiGate configuration using FortiGate global objects is imported into FortiManager, the global objects are added to the FortiManager as ADOM-level objects.

If FortiGate global objects (g-) are referenced in a FortiManager policy package, they are installed to the FortiGate Global VDOM and are usable in other VDOMs.

Below is a list of FortiGate global objects supported by FortiManager:

  • system replacemsg-group
  • system external-resource
  • webfilter profile
  • firewall wildcard-fqdn custom
  • ips sensor
  • sctp-filter profile
  • application list
  • dlp data-type
  • dlp dictionary
  • dlp sensor
  • dlp profile
  • webfilter search-engine
  • antivirus profile
  • file-filter profile
  • wireless-controller utm-profile
  • firewall ssh local-key
  • firewall ssh local-ca

Creating object configurations

You can create new object configurations before including them in policy packages. Alternatively, you can also create policy packages using existing object configurations.

To create objects in Global Database:
  1. Change the ADOM to Global Database.
  2. Go to Policy & Objects, and select your object type from the tree menu.
  3. Click Create New to create new objects.
  4. Click OK after creating the objects.
  5. (Optional) Additional object configuration options can be enabled in Tools > Feature Visibility.
FortiGate global objects

FortiManager supports FortiGate global objects. FortiGate global objects are identified with the prefix “g-“.

When a FortiGate configuration using FortiGate global objects is imported into FortiManager, the global objects are added to the FortiManager as ADOM-level objects.

If FortiGate global objects (g-) are referenced in a FortiManager policy package, they are installed to the FortiGate Global VDOM and are usable in other VDOMs.

Below is a list of FortiGate global objects supported by FortiManager:

  • system replacemsg-group
  • system external-resource
  • webfilter profile
  • firewall wildcard-fqdn custom
  • ips sensor
  • sctp-filter profile
  • application list
  • dlp data-type
  • dlp dictionary
  • dlp sensor
  • dlp profile
  • webfilter search-engine
  • antivirus profile
  • file-filter profile
  • wireless-controller utm-profile
  • firewall ssh local-key
  • firewall ssh local-ca