Ya know the thing I hate the most about #Fortinet? It isn't the ridiculously terrible code that has lead to numerous exploits. It isn't the absolutely shit hardware quality. It isn't even the fact that _every_ fucking product is called FortiSomething.
Although that last one is really fucking annoying.
It's that the FortiOS configuration is essentially a write once only thing. Any objects you create that become depended on by other objects, basically become immutable, or at least very firmly entrenched. To make changes or insert something new into the mix that changes the dependency hierarchy of objects will usually require massive changes. Often times, your only option is to delete huge sections of configuration, insert the new stuff, and then put the configuration right back again.
It fucking sucks.
Maybe they've fixed this in the 18+ months it has been since I have touched a Fortinet device, but I kind of doubt it. Fortinet has shown as a company, if nothing else, that they are dead set in their ways.
Please stop buying Fortinet products, you aren't buying security. You are paying money to have open exploits on your network, coupled with terrible network management tools.