Fortinet
NSE5_FMG-6.2 · Question #25
View the following exhibit, which shows the Download Import Report: Start to import config from devices:[remote-FortiGate] vdom:[root] to adom:[MYADOM], package:[remote-FortiGate] "firewall…
The correct answer is A. The address object used in policy ID 2 already exist in ADOM database with an interface association and conflicts with address object interface association locally on the FortiGate. See the full explanation below for the reasoning.
Question
View the following exhibit, which shows the Download Import Report:
Start to import config from devices:[remote-FortiGate] vdom:[root] to adom:[MYADOM], package:[remote-FortiGate]
"firewall address",SUCCESS,"[name=REMOTE_SUBNET,oid=580, new object]"
"firewall policy",SUCCESS,"[name=1,oid=990,new object]"
"firewall policy",FAIL,"[name=ID#2],oid=991, reason=interface(interface binding
Contradiction.detail:any->port0)binding fail]"
Why is it failing to import firewall policy ID 2?
Options
- AThe address object used in policy ID 2 already exist in ADOM database with an interface association and conflicts with address object interface association locally on the FortiGate
- BPolicy ID 2 is configured with interface any or port0. FortiManager expects to import this policy because any interface does not exist on FortiManager
- CPolicy ID 2 does not have ADOM interface mapping configured on FortiManager
- DPolicy ID 2 for this managed FortiGate already exists on FortiManager in policy package named Remote-FortiGate.
How the community answered
(33 responses)- A82% (27)
- B6% (2)
- C9% (3)
- D3% (1)
Community Discussion
No community discussion yet for this question.