Comprehensive and Detailed Explanation From Exact Extract of Network Security Support Engineer Study Guide (FortiOS 7.6) topics:
The correct answers are A and B . Security Fabric communication uses Fortinet-proprietary protocols, mainly FortiTelemetry and Neighbor Discovery . The study guide states that FortiTelemetry uses TCP port 8013 , and that the connection is always established by the downstream FortiGate toward the upstream FortiGate . This validates option A . The same section also states that FortiTelemetry must be manually enabled . More precisely, the upstream FortiGate interface must have Security Fabric Connection enabled under administrative access so it can accept incoming Security Fabric connection requests. This validates option B .
Option C is wrong because only the FortiTelemetry TCP port 8013 can be changed; Neighbor Discovery uses UDP port 8014 and cannot be changed. Option D is also wrong because Security Fabric communication is not enabled automatically among all Fortinet devices. It requires the correct Security Fabric settings, interface administrative access, and downstream authorization. The study guide’s troubleshooting section confirms that when FortiTelemetry is disabled, the upstream FortiGate receives TCP 8013 SYN packets but does not complete the Security Fabric connection.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit