Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Fortinet FCP_FMG_AD-7.6 Exam - Topic 2 Question 16 Discussion

Refer to the exhibits.An administrator must replace the source LAN interface in policy ID 2 on their FortiGateRugged-70F.However, when they try to install the policy package, they receive the error shown in the exhibit.What should the administrator do to resolve the error?
C) Create a per-device mapping for the LAN interface.
A) Use the API to assign a system template interface for FortiGateRugged-70F model.
B) Use a metadata variable to dynamically assign an interface when this error occurs.
D) Replace LAN with lan1, which is supported by FortiGateRugged-70F models.

Fortinet FCP_FMG_AD-7.6 Exam - Topic 2 Question 16 Discussion

Actual exam question for Fortinet's FCP_FMG_AD-7.6 exam
Question #: 16
Topic #: 2
[All FCP_FMG_AD-7.6 Questions]

Refer to the exhibits.

An administrator must replace the source LAN interface in policy ID 2 on their FortiGateRugged-70F.

However, when they try to install the policy package, they receive the error shown in the exhibit.

What should the administrator do to resolve the error?

Show Suggested Answer Hide Answer
Suggested Answer: C

The correct answer is C. The installation log explicitly says: ''Dynamic interface 'LAN' mapping undefined for device HQ-NGFW-1''. That means the policy is using a normalized interface, but FortiManager has no valid mapping for that device. The FortiManager 7.6 Administrator Study Guide states that ''Interfaces are mapped per device, per platform, or both'' and ''When the normalized interface is used in a policy, the per-device mappings have higher priority than per-platform mappings.''

The lab guide also shows that during import or policy mapping fixes, the administrator can set the Mapping Type to Per-Device for interfaces.

So the correct fix is to create a per-device mapping for the normalized interface LAN for that FortiGateRugged-70F. Hardcoding lan1 in the policy is not the best FortiManager method because interface mapping is designed specifically to avoid that.

=========


Contribute your Thoughts:

0/2000 characters
Carman
2 days ago
Wait, can you really use the API for this? Sounds a bit overkill.
upvoted 0 times
...
Yuriko
7 days ago
A per-device mapping could work too, but it seems more complicated.
upvoted 0 times
...
Luisa
12 days ago
I think option D is the way to go. lan1 is definitely supported.
upvoted 0 times
...
Carli
17 days ago
The API option sounds familiar, but I’m not confident it’s the best choice for this specific error. I might lean towards the lan1 replacement instead.
upvoted 0 times
...
Markus
23 days ago
I practiced a question about per-device mappings, but I can't recall if that applies here. It seems like it could be a solution.
upvoted 0 times
...
Daniel
28 days ago
I'm not entirely sure, but I feel like using a metadata variable could help with dynamic assignments. I’ve seen similar questions before.
upvoted 0 times
...
Lenora
1 month ago
I remember something about interface naming conventions in FortiGate devices. I think replacing LAN with lan1 might be the right move.
upvoted 0 times
...

Save Cancel