What is the best explanation of how FortiManager helps with mass provisioning?
C
Explanation:
FortiManager helps with mass provisioning by using templates that allow administrators to configure
the same settings on multiple FortiGate devices simultaneously, streamlining deployment and
management.
What is the purpose of ADOM revisions?
D
Explanation:
ADOM revisions save the current state of all policy packages and objects within an ADOM, allowing
administrators to track changes over time and revert to previous configurations if needed.
Refer to the exhibit.
An administrator assigned a new policy package to FortiGate HQ-NGFW-1. In the installation preview,
they noticed some settings they did not modify and are unsure about the changes.
Based on the exhibit, which two things will happen if they continue with the installation? (Choose
two.)
B, D
Explanation:
The configuration includes a server-list with server-type set to "update rating," which enables
FortiGate HQ-NGFW-1 to contact FortiManager as a FortiGuard Distribution Server (FDS) for
FortiGuard updates.
The installation includes a root_CA3 certificate, which FortiManager will install on FortiGate HQ-
NGFW-1 to authenticate FGFM tunnel connections between the devices.
Refer to the exhibit.
An administrator created two new meta fields in FortiManager.
Which operation can you perform with these parameters?
A
Explanation:
Meta fields in FortiManager can be added to objects as custom attributes, allowing administrators to
categorize and add additional information to firewall objects for easier management and
identification.
Push updates are failing on a FortiGate device located behind a network address translation (NAT)
device?
Which two settings should the administrator check to correct this problem? (Choose two.)
A, C
Explanation:
FortiManager must have the NAT device's IP address and correct ports configured to communicate
properly with the FortiGate behind NAT.
The NAT device must have the correct virtual IP address and ports configured to allow push updates
to reach the FortiGate device.
The administrator uses FortiManager to push a CLI script using the Remote FortiGate Directly (via
CLI) option to configure an IPsec VPN. However, when running the script, the administrator receives
the following error:
config vpn ipsec phase2-interface [parameter(s) invalid. detail: object mismatch]
What must the administrator do to resolve the script error and successfully apply the IPsec
configuration?
D
Explanation:
Running the script through the policy package or ADOM database method allows FortiManager to
properly interpret object relationships and dependencies in the IPsec configuration, preventing
object mismatch errors when pushing complex VPN settings directly via CLI.
An administrator has a FortiGate-HQ device with VDOMs—root, HR and Facilities, currently managed
under the FortiManager ADOM—Site1. They try to move VDOM HR to the FortiManager ADOM—
Site2, but it does not work.
Why is the administrator not able to move FortiGate-HQ VDOM HR to FortiManager ADOM—Site2?
A
Explanation:
FortiGate devices must be managed under the FortiManager ADOM corresponding to the root VDOM
to allow their individual VDOMs to be moved and managed in different ADOMs. Managing the root
VDOM in a different ADOM prevents moving subordinate VDOMs across ADOMs.
Refer to the exhibit.
FortiManager is operating behind a network address translation (NAT) device, and the administrator
configured the FortiManager NATed IP address under the FortiManager system administration
settings.
What is the expected result during discovery?
D
Explanation:
When FortiManager is behind a NAT device, setting the NATed IP address (100.65.0.120) in the
system admin settings causes FortiManager to use that NATed IP address for communication and
configuration with FortiGate during discovery and management operations.
An administrator configures a new BGP peer in the FortiManager device-level database of FortiGate.
They reinstall the policy package to the managed FortiGate device without any errors. However,
when the administrator logs in to FortiGate, they do not see the BGP configuration changes.
What is the most likely reason why FortiManager did not push the BGP peer changes to FortiGate?
B
Explanation:
If a BGP template is assigned to the FortiGate device on FortiManager, device-level BGP
configurations made directly in the device-level database are overridden by the template settings, so
the changes do not get pushed to the device.
Company policy dictates that any time a change is made to a policy package on FortiManager an
ADOM revision is created before the change installed, and that revision is held for a minimum of
90 days.
Over the past three months, each installed change has resulted in several unused policies and
duplicate objects.
The FortiManager administrator plans to upgrade the FortiGate devices and then upgrade the
FortiManager ADOM from version 7.4 to 7.6.
Which action can the administrator take to avoid slow ADOM upgrades?
D
Explanation:
Limiting ADOM revisions reduces the number of stored historical configurations, which helps avoid
performance degradation and slow ADOM upgrades caused by a large volume of revisions.