What must the administrator do to synchronize the address object?

Refer to the exhibits.

An administrator creates a new address object on the root FortiGate (Local-FortiGate) in the security fabric. After synchronization, this object is not available on the downstream FortiGate (ISFW).

What must the administrator do to synchronize the address object?
A . Change the csf setting on ISFW (downstream) to set configuration-sync local.
B . Change the csf setting on ISFW (downstream) to set authorization-request-type certificate.
C . Change the csf setting on both devices to set downstream-access enable.
D . Change the csf setting on Local-FortiGate (root) to set fabric-object-unification default.

Answer: C

Explanation:

C is correct because D is already set to default (Global CMDB objects will be synchronized in Security Fabric.)

The root device has downstream access disabled, so it needs to be enabled to sync the object.

downstream-access – Enable/disable downstream device access to this device’s configuration and data.

disable – Disable downstream device access to this device’s configuration and data.

The CLI command "set fabric-object-unification" is only available on the root FortiGate.

Subscribe
Notify of
guest
0 Comments
Inline Feedbacks
View all comments