NSE5_FMG-6.4 · Question #35
View the following exhibit, which shows the Download Import Report: Why it is failing to import firewall policy ID 2?
The correct answer is A. The address object used in policy ID 2 already exist in ADON database with any as interface association and conflicts with address object interface association. Explanation/Reference: FortiManager can create a dynamic mapping for an address object, if the address object name is the same, but contains a different value locally. However, there is one restriction - the associated interface cannot be different. This is because, at the ADOM…
Question
View the following exhibit, which shows the Download Import Report:
Why it is failing to import firewall policy ID 2?
Exhibit
Options
- AThe address object used in policy ID 2 already exist in ADON database with any as interface association and conflicts with address object interface association
- BPolicy ID 2 is configured from interface any to port6 FortiManager rejects to import this policy because any interface does not exist on FortiManager
- CPolicy ID 2 does not have ADOM Interface mapping configured on FortiManager
- DPolicy ID 2 for this managed FortiGate already exists on FortiManager in policy package named Remote-FortiGate.
How the community answered
(55 responses)- A82% (45)
- B11% (6)
- C5% (3)
- D2% (1)
Explanation
Explanation/Reference: FortiManager can create a dynamic mapping for an address object, if the address object name is the same, but contains a different value locally. However, there is one restriction - the associated interface cannot be different. This is because, at the ADOM level, this address object might be used by other policy packages, which might not have same interfaces." Address object name in this case is "REMOTE_SUBNET". The interface binding has 2 different interfaces 'ANY' and 'Port6'. They cannot be different.
Topics
Community Discussion
No community discussion yet for this question.
