Q: 10
Refer to the exhibit.
An administrator has created a firewall address object that is used in multiple policy packages for
multiple FortiGate devices in an ADOM.
After the installation operation is performed, which IP/netmask will be installed on Remote-Firewall
[VDOM1] for the LAN firewall address object?
An administrator has created a firewall address object that is used in multiple policy packages for
multiple FortiGate devices in an ADOM.
After the installation operation is performed, which IP/netmask will be installed on Remote-Firewall
[VDOM1] for the LAN firewall address object?Options
Discussion
A . C is tempting for the subnet but per-device mapping overrides default every time.
Option A is correct for this. With per-device mapping enabled, FortiManager pushes the mapped value (21.21.2.5/255.255.255.255) to Remote-Firewall [VDOM1], not the default address object value. Pretty sure that's how object overrides work, but open if someone sees it differently.
I remember a similar scenario from labs, in some exam reports and it matched A for Remote-Firewall when per-device mapping was set.
C or A. I get why some say C for the subnet, but with per-device mapping set for Remote-Firewall, I think it'd be A (21.21.2.5/32) that actually gets installed. Still possible to misread the intent here, so open to correction.
A is wrong, A. Official docs and FortiManager labs both point to per-device mapping taking precedence in this case.
A imo. Had something like this in a mock-per-device mapping always overrides the default address object, so Remote-Firewall [VDOM1] gets 21.21.2.5/32 that's shown in the mapping table. Not 100% if there's a gotcha but I'm pretty sure that's right.
C
Per-device mapping wins here, so it's A. Seen this in the official guide and some FortiManager demos, per-device overrides always take priority for specific installations. If I'm missing something let me know.
A. Per-device mapping should override the default, so Remote-Firewall gets 21.21.2.5/32 not the default value. Pretty sure that's how FortiManager handles it, but happy for a second opinion if anyone disagrees.
C/D? The per-device mapping trips people up. If you just looked at the default address you'd say D, but since Remote-Firewall [VDOM1] has its own entry (21.21.2.5/32) that's what actually gets pushed by FortiManager. I'm 90% sure it's A for this scenario, unless I missed something subtle in the exhibit.
Be respectful. No spam.