Look at the study guide on page 277 and 279, it clearly states that when the FMG is behind a NATed IP, then it is ONLY the FMG that can discover a new device, and also is the only one that can re-establish the FGFM tunnel after it is torn down. Literally stated on the first paragraph of page 277. Page 279 where both are NATed, affirms that the scenario plays out exactly the same as when only the FMG was NATed.
What I don't like about the question, is that A is also true, but only by deductive reasoning. So B and C are the better choices as they are clearly stated in the study guide as such.
Tricky one. It seems three answers are valid:
A. Correct. It can be configured on the FortiGate, but it is not by default.
B. Wrong. FortiManager does not attempt to reestablish the FGFM tunnel to the FortiGate NATed IP address.
C. Correct.
D. Correct.
D says "non-NATed", Fortigate wont be able to reach that address
upvoted 1 times
...
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
GeniusA
Highly Voted 5 months, 1 week agotalix
Highly Voted 5 months, 4 weeks agoRedrum702
Most Recent 1 month, 3 weeks agoGoodServant
2 months agojfff
3 months agoDatBroNZ
5 months, 3 weeks agoTTOG
5 months, 2 weeks ago