Courseiva

FortiManager Integration Steps for FortiGate Centralized Management

An administrator needs to integrate a FortiGate with FortiManager for centralized management. Which two steps are required? (Choose two.)

⚠ Common exam trap

Many candidates confuse SNMP (monitoring) or VPN (tunneling) as requirements for FortiManager integration, when in fact the FGFM protocol on TCP 541 and the registration command are the only mandatory steps.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a firewall policy allowing traffic from FortiGate to FortiManager on port 541 (FGFM).

FortiGate and FortiManager communicate using the FortiGate-to-FortiManager (FGFM) protocol over TCP port 541. A firewall policy must be configured on the FortiGate to allow outbound traffic to the FortiManager on this port, enabling registration and ongoing management. Option D is correct because the 'execute fortimanager register' command is the standard CLI method to initiate the registration process, providing the FortiManager IP address and optional registration code.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable SNMP on the FortiGate to allow FortiManager to monitor.

    Why it's wrong here

    Enabling SNMP on the FortiGate only allows external NMS platforms to poll or receive traps from the FortiGate; it does not participate in FortiManager's management channel. FortiManager uses the FGFM (FortiGate to FortiManager) protocol over TCP port 541 for configuration, retrieval, and statistics polling, not SNMP. Even if SNMP is enabled, the FortiGate will not appear as a managed device in FortiManager without proper FGFM registration and connectivity.

  • ✓

    Configure a firewall policy allowing traffic from FortiGate to FortiManager on port 541 (FGFM).

    Why this is correct

    FortiGate and FortiManager communicate exclusively via the FGFM protocol, which uses TCP port 541. A firewall policy must explicitly permit FortiGate-originated traffic to the FortiManager's IP address on port 541, otherwise registration and heartbeat messages are blocked. This policy is a prerequisite for both the 'execute fortimanager register' command and ongoing management operations, such as policy push and firmware updates.

  • ✗

    Configure a VPN tunnel between FortiGate and FortiManager.

    Why it's wrong here

    A VPN tunnel is only necessary if the FortiGate and FortiManager are separated by an untrusted network, but it is not a requirement for the FGFM management connection. FortiManager can manage FortiGates across a direct routed network, or even through NAT, as long as TCP 541 is reachable. In fact, FortiManager itself can be the VPN concentrator for managed FortiGates, but that is an additional feature, not a prerequisite for integration.

  • ✓

    Configure the FortiGate to connect to FortiManager using the 'execute fortimanager register' command.

    Why this is correct

    The 'execute fortimanager register' command is the required CLI step to bind a FortiGate to a specific FortiManager instance using an IP address and pre-shared registration key. This command initiates an FGFM handshake, exchanges digital certificates, and establishes the trust relationship, after which the FortiGate appears in FortiManager's managed devices list. Without this registration, even with firewall rules in place, FortiManager will not accept the FortiGate as a managed unit.

  • ✗

    Set the FortiGate's operation mode to transparent.

    Why it's wrong here

    Transparent mode changes how the FortiGate bridges layer-2 traffic, but does not affect the management plane connection to FortiManager. In both NAT/route and transparent modes, the FortiGate can initiate FGFM on TCP 541 and be managed by FortiManager. Therefore, switching operation mode is an unnecessary and unrelated step for integration, and could disrupt the network if done without planning.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.