nerdexam
Fortinet

NSE5_FMG-7.0 · Question #77

Refer to the exhibit.Review the Download Import Report. Why is it failing to import firewall policy ID 1?

The correct answer is D. The address object used in policy ID 1 already exists in the ADOM database with any as the. FortiManager can create a dynamic mapping for an address object, if the address object name is the same, but contains a different value locally. However, there is one restriction: the associated interface cannot be different. This is because, at the ADOM level, this address…

Policy and objects

Question

Refer to the exhibit.Review the Download Import Report. Why is it failing to import firewall policy ID 1?

Exhibit

NSE5_FMG-7.0 question #77 exhibit

Options

  • APolicy ID 1 for this managed FortiGate already exists on FortiManager in the policy package
  • BPolicy ID 1 is configured from the interface any to port6. FortiManager rejects the request to import
  • CPolicy ID 1 does not have the ADOM Interface mapping configured on FortiManager.
  • DThe address object used in policy ID 1 already exists in the ADOM database with any as the

How the community answered

(36 responses)
  • A
    6% (2)
  • B
    11% (4)
  • C
    6% (2)
  • D
    78% (28)

Explanation

FortiManager can create a dynamic mapping for an address object, if the address object name is the same, but contains a different value locally. However, there is one restriction: the associated interface cannot be different. This is because, at the ADOM level, this address object might be used by other policy packages, which might not have the same interfaces.

Topics

#policy import#address objects#ADOM database#import conflict

Community Discussion

No community discussion yet for this question.

Full NSE5_FMG-7.0 Practice