Fortinet black logo

Administration Guide

Using comment and name-based filters

Using comment and name-based filters

In profiles, filters can be applied to the following objects:

  • SD-WAN rules

  • Policies

  • Static routes

  • Firewall objects

Policies and static routes can be filtered on a value entered in the Comments field of the policy. SD-WAN rules and firewall objects can be filtered based on the Name field.

By default, objects that match will be excluded and ones that do not match will be shown.

The value you enter in the filter is matched against the beginning of the value.

For example, if you enter a policy filter of org1, it will match a policy with a comment value of org1 firewall policy but would not match firewall policy org1.

Tooltip

By default, filters exclude matched items. To change filters to include matched items, disable Exclude Filter for the filter type.

To limit access to policies, static routes, or firewall objects:
  1. In System > Profiles, click Create.

  2. Enter a name for the profile and set Profile Type to Customer.

  3. In Access Permissions , set the appropriate type to Read, Read/Write, or Custom.

  4. Enter a filter value in the appropriate field:

    • To filter SD-WAN rules, enter the filter value in SD-WAN > Name-based Filter(s).

    • To filter firewall objects, enter the filter value in Firewall Objects > Name-based Filter(s).

    • To filter policies, enter the filter value in Policies > Comment-based Filter(s).

    • To filter static routes, enter the filter value in Network > Static Route > Comment-based Filter(s).

  5. Enable or disable Exclude Filter. If Exclude Filter is disabled, matched items will be shown and items that do not match will be hidden.

  6. Click Save.

Using comment and name-based filters

In profiles, filters can be applied to the following objects:

  • SD-WAN rules

  • Policies

  • Static routes

  • Firewall objects

Policies and static routes can be filtered on a value entered in the Comments field of the policy. SD-WAN rules and firewall objects can be filtered based on the Name field.

By default, objects that match will be excluded and ones that do not match will be shown.

The value you enter in the filter is matched against the beginning of the value.

For example, if you enter a policy filter of org1, it will match a policy with a comment value of org1 firewall policy but would not match firewall policy org1.

Tooltip

By default, filters exclude matched items. To change filters to include matched items, disable Exclude Filter for the filter type.

To limit access to policies, static routes, or firewall objects:
  1. In System > Profiles, click Create.

  2. Enter a name for the profile and set Profile Type to Customer.

  3. In Access Permissions , set the appropriate type to Read, Read/Write, or Custom.

  4. Enter a filter value in the appropriate field:

    • To filter SD-WAN rules, enter the filter value in SD-WAN > Name-based Filter(s).

    • To filter firewall objects, enter the filter value in Firewall Objects > Name-based Filter(s).

    • To filter policies, enter the filter value in Policies > Comment-based Filter(s).

    • To filter static routes, enter the filter value in Network > Static Route > Comment-based Filter(s).

  5. Enable or disable Exclude Filter. If Exclude Filter is disabled, matched items will be shown and items that do not match will be hidden.

  6. Click Save.