Skip to Content

How to troubleshoot error when assigning global policy package

This article describes how to troubleshoot errors when assigning a global policy package to ADOM.

Sample error:

This article describes how to troubleshoot errors when assigning a global policy package to ADOM.

Scope

FortiManager.

Solution

Run the following debug command in FortiManager-CLI:

diag debug application securityconsole 255
diag debug enable

Assign the Global Policy Package from FMG-GUI and analyze the CLI output:

Assign the Global Policy Package from FMG-GUI and analyze the CLI output.

In this scenario, the issue is caused by empty ‘ssl-ssh-profile’ in the ‘profile group’:

In this scenario, the issue is caused by empty 'ssl-ssh-profile' in the 'profile group'.

To rectify this, add ‘ssl-ssh-profile’ in the ‘profile-group’.

To rectify this, add 'ssl-ssh-profile' in the 'profile-group'.

Once done, assign the policy package and verify if the issue is resolved.