nerdexam
Fortinet

NSE5_FMG-7.0 · Question #45

View the following exhibit, which shows the Download Import Report: Why it is failing to import firewall policy ID 2?

The correct answer is A. The address object used in policy ID 2 already exist in ADON database with any as interface. FortiManager can create a dynamic mapping for an address object, if the address object name is the same, but contains a different value locally. However, there is one restriction: the associated interface cannot be different. This is because, at the ADOM level, this address…

Troubleshooting

Question

View the following exhibit, which shows the Download Import Report:

Why it is failing to import firewall policy ID 2?

Exhibit

NSE5_FMG-7.0 question #45 exhibit

Options

  • AThe address object used in policy ID 2 already exist in ADON database with any as interface
  • BPolicy ID 2 is configured from interface any to port6 FortiManager rejects to import this policy
  • CPolicy ID 2 does not have ADOM Interface mapping configured on FortiManager
  • DPolicy ID 2 for this managed FortiGate already exists on FortiManager in policy package named

How the community answered

(26 responses)
  • A
    73% (19)
  • B
    8% (2)
  • C
    15% (4)
  • D
    4% (1)

Explanation

FortiManager can create a dynamic mapping for an address object, if the address object name is the same, but contains a different value locally. However, there is one restriction: the associated interface cannot be different. This is because, at the ADOM level, this address object might be used by other policy packages, which might not have the same interfaces.

Topics

#policy import failure#address objects#interface mapping#ADOM database

Community Discussion

No community discussion yet for this question.

Full NSE5_FMG-7.0 Practice