Install policy package
If you do not have a policy package assigned to your FortiGate(s), the best way to install a policy package for the first time is by using the Install Wizard and the Install Policy Package & Device Settings operation. This operation takes ADOM and policy layer information (from the Policies & Objects module) and installs the settings to the device layer, and the difference from the device layer is installed to the FortiGate(s).
You can access an installation preview for this operation. If you do not want to install the changes, you can cancel the operation without modifying anything.
See Installing policy packages and device settings.
FGFM recovery
When FortiManager installs policy packages to a FortiGate, the FortiGate will restart the FGFM tunnel after each installation and attempt to reconnect to FortiManager. If the reconnection fails, the FortiGate will reboot to recover the previous configuration from its config file and attempt to reestablish the connection with FortiManager.
You can prevent the FortiGate reboot from occurring in a rollback scenario using the following command:
config system dm
set rollback-allow-reboot {enable |disable}
end