FCSS_EFW_AD-7.4 · Question #9
An administrator must standardize the deployment of FortiGate devices across branches with consistent interface roles and policy packages using FortiManager. What is the recommended best practice…
The correct answer is A. Enable metadata variables to use dynamic configurations in the standard interfaces of. When standardizing the deployment of FortiGate devices across branches using FortiManager, the best practice is to use metadata variables. This allows for dynamic interface configuration while maintaining a single, consistent policy package for all branches. Metadata variables…
Question
An administrator must standardize the deployment of FortiGate devices across branches with consistent interface roles and policy packages using FortiManager. What is the recommended best practice for interface assignment in this scenario?
Options
- AEnable metadata variables to use dynamic configurations in the standard interfaces of
- BUse the Install On feature in the policy package to automatically assign different interfaces
- CCreate interfaces using device database scripts to use them on the same policy package of
- DCreate normalized interface types per-platform to automatically recognize device layer
How the community answered
(20 responses)- A80% (16)
- B10% (2)
- C5% (1)
- D5% (1)
Explanation
When standardizing the deployment of FortiGate devices across branches using FortiManager, the best practice is to use metadata variables. This allows for dynamic interface configuration while maintaining a single, consistent policy package for all branches. Metadata variables in FortiManager enable interface roles and configurations to be dynamically assigned based on the specific FortiGate device. This ensures scalability and consistent security policy enforcement across all branches without manually adjusting interface settings for each device. When a new branch FortiGate is deployed, metadata variables automatically map to the correct physical interfaces, reducing manual configuration errors.
Topics
Community Discussion
No community discussion yet for this question.