FCP Fortinet Security Fabric Integration & Troubleshooting 3 — Questions and Answers
Question 1: Which protocol does FortiGate use by default to communicate with other Security Fabric members for topology discovery and synchronization?
- HTTPS on port 443
- FortiLink on port 8013
- Security Fabric over TCP port 8013 (Correct answer)
- OFTP on port 514
Correct answer: Security Fabric over TCP port 8013
Security Fabric members communicate using a proprietary protocol over TCP port 8013 for topology and synchronization data.
Question 2: An administrator wants FortiClient registered to FortiClient EMS to automatically receive posture tags that are then enforced by FortiGate policy. Which configuration is required?
- Configure a RADIUS server on FortiGate pointing to EMS
- Add FortiClient EMS as a Fabric Connector on the root FortiGate (Correct answer)
- Enable FortiClient telemetry on FortiAnalyzer
- Install FortiAuthenticator between EMS and FortiGate
Correct answer: Add FortiClient EMS as a Fabric Connector on the root FortiGate
Adding FortiClient EMS as a Fabric Connector allows FortiGate to pull EMS endpoint tags and use them as dynamic firewall policy conditions.
Question 3: When a FortiSwitch is managed by FortiGate via FortiLink, which statement about VLAN provisioning is correct?
- VLANs must be configured directly on FortiSwitch CLI before FortiGate can use them
- FortiGate pushes VLAN and port configurations to FortiSwitch through the FortiLink interface (Correct answer)
- VLANs are synchronized from FortiManager to FortiSwitch bypassing FortiGate
- FortiSwitch uses STP BPDU to learn VLANs from the FortiGate
Correct answer: FortiGate pushes VLAN and port configurations to FortiSwitch through the FortiLink interface
In FortiLink mode, FortiGate acts as the controller and pushes all VLAN and port configurations down to managed FortiSwitch units.
Question 4: A Security Fabric topology shows a FortiAP in 'Offline' state despite the AP being physically connected and powered. What is the most likely troubleshooting step?
- Reboot the FortiAnalyzer to refresh the topology database
- Verify the FortiGate wireless controller settings and check for CAPWAP tunnel connectivity to the AP (Correct answer)
- Re-pair the FortiAP with FortiManager using its serial number
- Check that the FortiAP firmware matches the FortiGate firmware exactly
Correct answer: Verify the FortiGate wireless controller settings and check for CAPWAP tunnel connectivity to the AP
FortiAP offline status typically indicates a CAPWAP tunnel failure between the AP and the FortiGate wireless controller, which should be verified first.
Question 5: What does the 'Security Rating' check 'Admin Accounts with Default Passwords' specifically evaluate?
- Whether any administrator still uses the factory-default 'admin' password on Fabric-connected devices (Correct answer)
- Whether all admin accounts use multi-factor authentication
- Whether password complexity policies are enforced on all FortiGates
- Whether guest administrator accounts are disabled
Correct answer: Whether any administrator still uses the factory-default 'admin' password on Fabric-connected devices
This Security Rating check flags any Fabric-connected device where the admin account retains the factory-default empty or 'admin' password.
Question 6: In a Security Fabric with FortiAnalyzer, what log type must be enabled on FortiGate for the 'Compromised Hosts' widget in FortiView to populate correctly?
- Traffic logs with all sessions enabled
- Application control logs only
- Security logs including antivirus, IPS, and web filter events (Correct answer)
- System event logs forwarded via SNMP
Correct answer: Security logs including antivirus, IPS, and web filter events
The Compromised Hosts widget relies on security event logs (antivirus, IPS, web filter) forwarded to FortiAnalyzer to identify and score compromised endpoints.
Question 7: Which action should an administrator take when the Security Fabric shows an 'Upstream FortiGate Mismatch' warning for a downstream unit?
- Reinstall the downstream FortiGate's firmware from USB
- Verify that the downstream FortiGate's configured upstream IP and pre-shared key match the root FortiGate's Fabric settings (Correct answer)
- Delete and re-add the downstream device in FortiManager
- Change the Security Fabric group name on both devices to match
Correct answer: Verify that the downstream FortiGate's configured upstream IP and pre-shared key match the root FortiGate's Fabric settings
An upstream mismatch warning indicates the downstream FortiGate's Fabric configuration (upstream IP or pre-shared key) does not align with the root FortiGate's settings.
Which protocol does FortiGate use by default to communicate with other Security Fabric members for topology discovery and synchronization?