FortiManager: The “Surgical” Script Method

This method is a clean way to update the FortiManager database directly, ensuring the profile is ready to push to managed devices. This is particularly useful when resolving discrepancies between a FortiGate device’s configuration and what is managed by FortiManager through the UI.

How to Use the “Surgical” Script Method

  1. Go to Device Manager > Scripts.

  2. Click Create New.

  3. Script Name: Fix_AI_Category (or a descriptive name for your task).

  4. Script Target: Change this to “ADOM Database”.

    • IMPORTANT: Do not select “Remote Device” for the script target. Selecting “ADOM Database” ensures the script modifies the FortiManager’s internal database representation of the device configuration, rather than attempting to run commands directly on the FortiGate. This is what enables the “import” functionality.
  5. Script Content: Paste the FortiGate CLI commands that you want to effectively “import” or synchronize into the FortiManager’s database for the specific device or ADOM.

    Example Script Block:

    config firewall profile
        edit <profile-name>
            set log-flow all
            set comments "Updated from FortiGate CLI"
        next
    end
    

    Replace <profile-name> and the content with the actual configuration you wish to synchronize.

Understanding the Impact

When this script is run against the “ADOM Database” target, FortiManager processes the CLI commands as if they were applied to its internal representation of the FortiGate’s configuration. This updates the FortiManager’s database, aligning it with (or making the desired changes for) the FortiGate’s actual or intended configuration.

After successfully running such a script, the FortiManager GUI will reflect these changes, and you will typically be able to then install/push this updated configuration to the actual FortiGate device if required, or resolve the discrepancy flag.

This method allows you to “export” FortiGate CLI configurations into FortiManager’s database, effectively bypassing potential UI limitations or complex reconfigurations within FortiManager itself.