Been wrestling with address object management in our FortiGate setup for a while. We have a pretty dynamic CMDB, and keeping firewall policies in sync manually was a huge pain point—and a real risk for misconfigurations.
I finally carved out some time last week and built a Python script that pulls address objects and groups from our CMDB API and pushes updates to the FortiGate via its REST API. It handles creates, updates, and even deletes (with careful logic, of course). The initial setup took a bit to get the authentication and error handling right, but it's running like a charm now.
It's already saving our team a few hours every week we used to spend on manual entry and validation. More importantly, the data quality is so much better—no more typos in IP ranges. I'm curious if anyone else has tackled similar automation between their configuration management databases and FortiGate. What was your approach? Any pitfalls I should watch out for as we scale this?