Refer to the exhibits. An administrator creates a new address object on the root FortiGate (Local-FortiGate) in the security fabric. After synchronization, this object is not available on the downstream FortiGate (ISFW). What must the administrator do to synchronize the address object?



Select an option, then click Submit answer.
Reference / correct answer:
Change the csf setting on Local-FortiGate (root) to set fabric-object-unification default.
Most accepted answer: A. Change the csf setting on Local-FortiGate (root) to set fabric-object-unification default.
Community votes: A=8, B=1
Selected Answer: A The CLI command fabric-object-unification is available only on the root FortiGate device. When set to local, global objects are not synchronized to downstream devices in the Security Fabric. The default value is default. upvoted 1 times
Selected Answer: A A is correct upvoted 1 times
Selected Answer: A Set object synchronization (fabric-object-unification) to default or local on a downstream device. When set to local, the device does not synchronize objects from the root, but will still participate in sending the synchronized object downstream. https://docs.fortinet.com/document/fortigate/6.4.0/new-features/520820/improvements-to-synchronizing-objects-across-the-security-fabric-6-4-4 upvoted 1 times
Selected Answer: A set fabric-object-unification [default/local] default: Global CMDB objects will be synchronized in the Security Fabric. local: Global CMDB objects will not be synchronized to and from this device. https://docs.fortinet.com/document/fortigate/7.4.3/administration-guide/880913/synchronizing-objects-across-the-security-fabric?utm_source=chatgpt.com upvoted 1 times
Selected Answer: B The downstream-access setting in the FortiGate Security Fabric configuration determines whether downstream devices have access to the fabric objects and configuration from the root FortiGate. Enabling this setting ensures that changes made on the root FortiGate are properly synchronized and visible on downstream FortiGates. By setting downstream-access enable on both the root and downstream FortiGates, you ensure that the synchronization of configuration objects, such as address objects, is correctly managed. upvoted 1 times