QuestionQ26

Central management

You have configured the FortiGate devices in an enterprise network to join the Fortinet Security Fabric. You have a list of IP addresses that must be blocked by the data center firewall, and the list is updated daily.

How can you automate firewall-policy updates to add the IP addresses from the daily updated list?

  • A With an external connector from External Feeds
  • B With metadata variables in FortiManager
  • C With a CLI script in FortiManager
  • D With a Security Fabric automation
Explanation

An IP address external feed dynamically imports an address list from an external server and periodically synchronizes its updates. The imported feed can be used as a source or destination address in a FortiGate firewall policy, including a deny policy, so newly listed IP addresses are enforced without manual policy edits.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!