Courseiva
Enterprise Firewall and VDOMsmediumMultiple ChoiceObjective-mapped

NSE7 Enterprise Firewall and VDOMs Practice Question

An administrator uses FortiManager to deploy a new security policy to a remote FortiGate. The administrator selects 'Install Preview' and sees that the policy will be created. After confirming, the installation fails with 'Device not reachable'. What is the most likely reason?

⚠ Common exam trap

Candidates often confuse a 'Device not reachable' error with configuration or policy issues, such as memory or lock conflicts, when the root cause is almost always a network connectivity problem, specifically related to NAT or firewall rules blocking FGFM traffic.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The FortiGate is behind a NAT device that blocks FGFM traffic

The 'Device not reachable' error during an Install Preview operation indicates that FortiManager cannot establish or maintain the FGFM (FortiGate-to-FortiManager) tunnel with the remote FortiGate. When the FortiGate is behind a NAT device, the NAT may alter the source IP or port of FGFM traffic, causing the tunnel to break or preventing the FortiManager from reaching the FortiGate's management IP. This is the most common cause of such reachability failures in remote deployments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The FortiGate has insufficient memory

    Why it's wrong here

    Insufficient memory would cause other symptoms.

  • The policy package is locked by another administrator

    Why it's wrong here

    Locking prevents editing, not installation.

  • The FortiGate's configuration revision has changed since the last sync

    Why it's wrong here

    This would cause a conflict warning, not a reachability error.

  • The FortiGate is behind a NAT device that blocks FGFM traffic

    Why this is correct

    FGFM uses TCP 541, which must be allowed and reachable.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

Courseiva writes every NSE7 question from scratch — 940 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.