<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Fortinet User configuration in SmartMove</title>
    <link>https://community.checkpoint.com/t5/SmartMove/Fortinet-User-configuration/m-p/146918#M454</link>
    <description>&lt;P&gt;Hi Ofir!&lt;/P&gt;
&lt;P&gt;Then could you please clarify what is meant by this statement in the SK?&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="100%"&gt;&lt;STRONG&gt;Users&lt;/STRONG&gt;&lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;SmartMove cannot create LDAP account unit objects that are needed for the user configuration process. You will need to create this object manually and provide the name of this object to SmartMove for conversion.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also this is confusing:&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="100%"&gt;
&lt;UL&gt;
&lt;LI&gt;Only Firewall, NAT and &lt;STRONG&gt;Users/Groups configuration (AD)&lt;/STRONG&gt; will be converted (including network objects, services, and schedules).&lt;/LI&gt;
&lt;/UL&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What users are converted?&lt;/P&gt;</description>
    <pubDate>Sun, 24 Apr 2022 07:28:40 GMT</pubDate>
    <dc:creator>Denis_Romanov</dc:creator>
    <dc:date>2022-04-24T07:28:40Z</dc:date>
    <item>
      <title>Fortinet User configuration</title>
      <link>https://community.checkpoint.com/t5/SmartMove/Fortinet-User-configuration/m-p/146817#M450</link>
      <description>&lt;P&gt;Hi! I have a Fortigate configuration (v.6.09) and trying to convert AD groups however it seems those are just ignored in the conversion process for some reason. I've specified an LDAP Account Unit (which is needed to generate a valid mgmt_cli commands) but Access Roles are not created during the conversion.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is how it looks in Fortigate config:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;    edit "AD_group_test"
        set member "AD_LDAP_AU"
        config match
            edit 1
                set server-name "AD_LDAP_AU"
                set group-name "CN=AD_group_test,OU=InfoSec,OU=Test,OU=Groups,OU=DC01,DC=test,DC=local"
            next
        end&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;And this group is used in the Firewall policy:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;    edit 20911
        set uuid 0e48bc7a-bf0b-51ec-d77a-8de1cc2533c7
        set srcintf "any"
        set dstintf "any"
        set srcaddr "Private_nets"
        set dstaddr "10.0.0.1" "10.0.0.2" "10.0.0.3" "Net_10.0.1.0/24"
        set action accept
        set schedule "always"
        set service "ALL"
        set logtraffic all
        set groups "AD_group_test"
        set global-label "General rules"
    next&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;But SmartMove doesn't generate any Access Role objects (x0)..&lt;/P&gt;
&lt;P&gt;Any input on what may be wrong here? From Release Notes it seems that it should be supported..&lt;BR /&gt;I'm using the latest SmartMove version 6.0.8068.6581.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2022 06:57:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/Fortinet-User-configuration/m-p/146817#M450</guid>
      <dc:creator>Denis_Romanov</dc:creator>
      <dc:date>2022-04-22T06:57:45Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinet User configuration</title>
      <link>https://community.checkpoint.com/t5/SmartMove/Fortinet-User-configuration/m-p/146917#M453</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;SmatMove does not generate&amp;nbsp;&lt;SPAN&gt;AD groups, you will need manually&amp;nbsp;to generate it.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Apr 2022 07:03:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/Fortinet-User-configuration/m-p/146917#M453</guid>
      <dc:creator>Ofir_Shikolski</dc:creator>
      <dc:date>2022-04-24T07:03:14Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinet User configuration</title>
      <link>https://community.checkpoint.com/t5/SmartMove/Fortinet-User-configuration/m-p/146918#M454</link>
      <description>&lt;P&gt;Hi Ofir!&lt;/P&gt;
&lt;P&gt;Then could you please clarify what is meant by this statement in the SK?&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="100%"&gt;&lt;STRONG&gt;Users&lt;/STRONG&gt;&lt;BR /&gt;
&lt;UL&gt;
&lt;LI&gt;SmartMove cannot create LDAP account unit objects that are needed for the user configuration process. You will need to create this object manually and provide the name of this object to SmartMove for conversion.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also this is confusing:&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="100%"&gt;
&lt;UL&gt;
&lt;LI&gt;Only Firewall, NAT and &lt;STRONG&gt;Users/Groups configuration (AD)&lt;/STRONG&gt; will be converted (including network objects, services, and schedules).&lt;/LI&gt;
&lt;/UL&gt;
&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What users are converted?&lt;/P&gt;</description>
      <pubDate>Sun, 24 Apr 2022 07:28:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/Fortinet-User-configuration/m-p/146918#M454</guid>
      <dc:creator>Denis_Romanov</dc:creator>
      <dc:date>2022-04-24T07:28:40Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinet User configuration</title>
      <link>https://community.checkpoint.com/t5/SmartMove/Fortinet-User-configuration/m-p/146922#M455</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/940"&gt;@Denis_Romanov&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;Can you please send me the config file? &lt;A href="mailto:ofirs@checkpoint.com" target="_blank"&gt;ofirs@checkpoint.com&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it is working for me &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 24 Apr 2022 10:57:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/Fortinet-User-configuration/m-p/146922#M455</guid>
      <dc:creator>Ofir_Shikolski</dc:creator>
      <dc:date>2022-04-24T10:57:55Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinet User configuration</title>
      <link>https://community.checkpoint.com/t5/SmartMove/Fortinet-User-configuration/m-p/146932#M456</link>
      <description>&lt;P&gt;Not sure why it fails for you...I did this conversion before and it converted everything.&lt;/P&gt;</description>
      <pubDate>Sun, 24 Apr 2022 21:59:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/Fortinet-User-configuration/m-p/146932#M456</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-04-24T21:59:03Z</dc:date>
    </item>
    <item>
      <title>Re: Fortinet User configuration</title>
      <link>https://community.checkpoint.com/t5/SmartMove/Fortinet-User-configuration/m-p/150744#M460</link>
      <description>&lt;P&gt;The issue was: not object were found in the config file.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2022 05:41:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SmartMove/Fortinet-User-configuration/m-p/150744#M460</guid>
      <dc:creator>Ofir_Shikolski</dc:creator>
      <dc:date>2022-06-14T05:41:00Z</dc:date>
    </item>
  </channel>
</rss>

