The exhibit identifies the root VDOM as the management VDOM, indicated by the green check mark. The Enterprise Firewall 7.6 Administrator Study Guide explains that the management VDOM handles FortiGuard database downloads, license validation, and FortiGuard rating connectivity on behalf of the entire FortiGate system. It states that FortiGuard updates obtained through the management VDOM “will affect all VDOMs.”
Consequently, the root VDOM must reach either a public Fortinet Distribution Network server or a FortiManager configured as a FortiGuard Distribution Server in an isolated environment. The guide specifically identifies connectivity to “a FortiManager serving as a FortiGuard Distribution Server (FDS) in a closed network” as the alternative to public FortiGuard access. Loss of both paths prevents Core1 and Core2 from using current FortiGuard web-filtering information. Therefore, options A and B are correct.
Core1 and Core2 do not need to become management VDOMs; FortiGate uses one designated management VDOM for these system-level services. A VDOM link is used to route user traffic between VDOMs and is not required for distributing FortiGuard services, eliminating option D.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit