Refer to the exhibits.



FortiGate HQ-NGFW-1 downloads and validates FortiGuard databases from FortiManager which acts as a local FortiGuard Distribution Server (FDS) in a closed network. An administrator pushes a new firewall policy with an intrusion prevention system (IPS) profile from FortiManager to FortiGate HQ- NGFW-1 However, FortiGate does not recognize the new IPS signature from FortiManager.
What is the most likely reason why FortiGate HQ-NGFW-1 does not recognize the new IPS signature?
- FortiGate must enable rating for the FortiManager IP address, 192.168.1.120, in server list 1.
- FortiManager and FortiGate have different IPS database versions.
- The administrator must enable IPv6 connections for FortiGuard services on FortiManager.
- The administrator must enable the fortiguard-anycast option to correctly download all signatures from the local FDS.
Answer(s): B
Explanation:
The most likely reason FortiGate HQ-NGFW-1 does not recognize the new IPS signature is that FortiManager and FortiGate have different IPS database versions. The FortiManager may have pushed a signature update that FortiGate has not yet synchronized or validated locally, causing the signature to be unrecognized.
Reveal Solution Next Question