FCSS_LED_AR-7.6 · Question #71
A network administrator connects a new FortiGate to the network, allowing it to automatically discover andI register with FortiManager. What occurs after FortiGate retrieves the FortiManager address?
The correct answer is A. FortiGate establishes a secure tunnel to FortiManager over TCP port 541. When a FortiGate is deployed usingZero Touch Provisioning (ZTP)or auto-discovery: FortiGate retrieves theFortiManager IP address(from DHCP Option 240, FortiCloud/ZTNA provisioning, or manual set). The next step isnot UI authorizationor DHCP changes--it immediately attempts to…
Question
A network administrator connects a new FortiGate to the network, allowing it to automatically discover andI register with FortiManager. What occurs after FortiGate retrieves the FortiManager address?
Options
- AFortiGate establishes a secure tunnel to FortiManager over TCP port 541.
- BThe device needs to be manually authorized on FortiManager.
- CFortiGate configures its interface settings based on a DHCP response from FortiManager.
- DFortiGate sends a discovery request to all devices on the local network using UDP port 1068.
How the community answered
(42 responses)- A86% (36)
- B7% (3)
- C2% (1)
- D5% (2)
Explanation
When a FortiGate is deployed usingZero Touch Provisioning (ZTP)or auto-discovery: FortiGate retrieves theFortiManager IP address(from DHCP Option 240, FortiCloud/ZTNA provisioning, or manual set). The next step isnot UI authorizationor DHCP changes--it immediately attempts to form aFGFM (FortiGate-FortiManager) tunnel. The FGFM protocol uses TCP port 541to establish a secure management channel. FortiManager will still require manual authorization of the deviceinside FortiManager, but this occursafterthe tunnel is established. Therefore, the first automatic action after retrieving the FMG address iscreating the secure FGFM tunnel on TCP/541.
Topics
Community Discussion
No community discussion yet for this question.