02. Administration And Management Flashcards

1
Q

Enable ADOM

A
  1. From gui > system info > admin domain
  2. From CLI
    Conf sys global
    Set adom-status enable/disable
    End
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Admin with what profile can enable ADOMS

A

Super_User

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

ADOM can be created in which modes

A
  1. Normal - full access to make config changes for ADOM and devices from FMG
  2. Backup - backup config changes made directly on managed device
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How frequently config changes are checked in normal ADOM mode?

A

Every 5 sec diff config sent to FMG

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What protocol is used to send config diff

A

FortiGate-FortiManager communication protocol (FGFM)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

Limitation of auto update?

A

updates only device manager changes and not policy and object changes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

Backup mode ADOM

A
  1. Read only
  2. Not all management panes available. AP Manager, VPN Manager, FortiSwitch Manager are not available
  3. can add and delete devices, but the device-level settings are not available for configuration and installation.
  4. can import firewall address and service objects into FortiManager, and FortiManager stores the objects in the Device Manager database. You can view the objects on the Policy & Objects pane. Although you can view the objects on the Policy & Objects pane, the objects are not stored in the central database. This lets you maintain a repository of objects used by all devices in the backup ADOM that is separate from the central database.
  5. Only use the script feature on FortiManager to make configuration changes to managed devices.
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is the difference between normal and advanced ADOM device modes

A
  1. Normal -all VDOMs on same FGT to same ADOM only
  2. Advanced - can assign different VDOMs from the same FortiGate device to different ADOMs
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

At what level ADOM device mode is applied

A

Globally to all ADOMs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is the main purpose of backup ADOM

A. To maintain backup config of managed devices
B. To install policy package changes offline

A

A. To maintain backup config of managed devices

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Which action can you perform in advanced VDOMs mode

A. Assign different VDOMs from same FGT to different ADOMs
B. Assign same VDOM to different ADOMs

A

A. Assign different VDOMs from same FGT to different ADOMs

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

Super_User

A

All system permissions
All device permissions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Standard_User

A

No system permissions
RW all device permissions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Restricted_User

A

No system permissions
RO device permissions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

Package_User

A

RW access to policy packages and object permissions
RO access to system and another permissions

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Types of administrator profiles defined in profile settings

A

System admin - allow them to view and configure as much, or as little, as required
Restricted admin - make changes to the web filtering profile, IPS sensor, and application sensor associated with their ADOM

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

Methods to control and restrict administrator access

A
  • Administrative profiles
  • ADOMs
  • Trusted hosts
  • all or selected policy packages
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
18
Q

External user authentication servers

A
  1. LDAP
  2. RADIUS
  3. TACACS+
  4. PKI
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
19
Q

track installation changes from the FortiManager user from FortiGate

A

Log & Report > Events on the managed FortiGate device

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
20
Q

How can you restrict admin access only to a few ADOMS on FMG

A. By disabling concurrent access to ADOMs
B. By assigning ADOMs to admin account

A

B. By assigning ADOMs to admin account

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
21
Q

Which feature is available in Restricted admin profile

A. Device registration
B. IPS sensor

A

B. IPS sensor

22
Q

Default workspace mode status

A

Disabled.

By default, multiple administrators can access same ADOM concurrently because workspace-mode is set to disabled.

Conf sys global
Set workspace-mode disabled/normal
End

23
Q

What does Workspace mode do

A

Disables concurrent ADOM access
Adds ADOM locking
You must lock ADOM, device or policy package
RW access for only one admin. Other admin will have RO access

Conf sys global
Set workspace-mode normal
End

24
Q

What happens to device/policy lock if you lock whole ADOM

A

Locking an ADOM automatically removes locks on devices and policy packages that you have locked within
that ADOM.

25
Q

Workspace GUI icons

A

Green lock - RW admin access. Locked by me
Red lock - RO admin access. Locked by another admin
Grey lock - ADOM is unlocked

26
Q

Locking devices when ADOMs are in advanced mode

A

You cannot lock individual device

27
Q

When should you consider using workspace mode

A. When multiple admins require concurrent access
B. When multiple managed FGT devices have a single admin

A

A. When multiple admins require concurrent access

28
Q

Which statement locking ADOM is true

A. It auto remove locks,on devices and policies
B. Other admins have RW access

A

A. It auto remove locks,on devices and policies

29
Q

How many firmware versions can be managed by ADOM?

A

An ADOM can concurrently manage FortiGate devices running two FortiGate firmware versions; for example, FortiOS 6.2 and 6.4.

30
Q

What will not happen to ADOM when you upgrade device to new firmware?

A

upgrading the FortiManager firmware version will not upgrade the ADOM version.

31
Q

When should you perform ADOM upgrade

A

Upgrade ADOM version once you upgraded all devices in this ADOM to new version

Starting in FortiManager 7.0.0, you can upgrade ADOM version 6.2 to 6.4 without first updating all devices in
the ADOM from FortiOS 6.2 to 6.4. In the older version ADOM, upgrade ForiGate devices first and then the
ADOM version.

32
Q

ADOM upgrade debugging CLI commands

A

Diag debug en
Diag debug service cdb 255

33
Q

What will not happen automatically when you Move device from one ADOM to another ADOM

A

policies and objects are not imported into the ADOM database.
You must run the Import Policy wizard to import policies and objects into the ADOM database.
Moving devices from one ADOM to another is not a recommended practice.
For example, if you have configured complex IPsec VPNs with VPN Manager, you will need to reconfigure the VPN settings after you move the IPsec VPNs from one ADOM to another

34
Q

Procedure to Migrate upgraded device to another ADOM

A
  1. Upgrade device
  2. Move to new ADOM
  3. Import policy and objects to new ADOM
35
Q

ADOM best practice- before upgrade

A

1.install any pending device settings or policy package changes
2. Ensure device setting and policy packages are all synchronized

36
Q

ADOM best practice- after upgrade

A
  1. perform the installation preview. The Install preview shows you any changes that occurred during the upgrade process.
  2. check that all the to-be-installed changes are acceptable. make corrections if required
37
Q

Which step should you take as best practice after FGT firmware upgrade

A. Push policy package and run script to update objects
B. Upgrade ADOM and retrieve config

A

B. Upgrade ADOM and retrieve config

38
Q

What FortiManager backup includes and what not

A

Includes:
All devices
Global db
Flash config

Does NOT include logs, FortiGuard cache, and firmware images saved on FortiManager

39
Q

Schedule backups

A

From CLI only (ftp, scp, sftp)

40
Q

How to perform FortiManager restore. Requirements and limitations

A

From GUI or CLI
After restore FMG reboots
Must be same firmware version and same model

Exe restore all-settings <……..>

41
Q

Migrate FMG config from one model to another

A

back up the configuration on one FortiManager model, and then run the CLI migrate command on the second FortiManager.

Exe migrate all-settings ftp/scp/sftp <server> <filepath> <user> <pass> <cryptpass></cryptpass></pass></user></filepath></server>

42
Q

FGFM management protocol port

A

TCP/541

43
Q

Offline mode

A

By default disabled
Enabled after backup restoration
Can’t manage devices in offline mode

44
Q

Reset FMG

A

Exe reset all-settings - returns FortiManager to its factory default settings and reboots FortiManager.
Exe reset all-except-ip -

Exe format <disk….> -

erases all device settings and images, FortiGuard databases, and log data on the FortiManager hard drive.
To completely erase all configuration databases, reset all settings, then format the disk using the CLI.

Even if you format your disks, this only destroys the file system tables. Files remain. Use deep-erase flag

45
Q

What is included in FMG backup

A. Logs and firmware images
B. Global db and all devices

A

B. Global db and all devices

46
Q

Which statement about FMG backup is true

A. It supports FTP, SCP and SFTP
B. Can be configured using CLI and GUI

A

B. Can be configured using CLI and GUI (regular backup, not schedules)

47
Q

Default event log severity

A

Information

48
Q

How can you change event log severity level

A

From CLI only

49
Q

WSDL interface

A

use web services to monitor system.
Can Download definition file. The file itself defines the format of commands FortiManager will accept, as well as the response to expect.

50
Q

When should admin use event logs at debug level

A. When troubleshooting FMG with TAC
B. When searching for admin login event

A

A. When troubleshooting FMG with TAC

51
Q

What is the main purpose of using APIs on FMG

A. To manage FMG using 3rd party software and hardware
B. To manage devices without FMG license

A

A. To manage FMG using 3rd party software and hardware