Question 1
Question
The cluster assigns virtual IP addresses to heartbeat interfaces based on each FortiGate’s serial number, what subnet use?
Answer
-
169.254.0.0
-
254.169.0.0
-
169.0.254.0
-
254.0.169.0
Question 2
Question
FortiGates keep their heartbeat virtual IP addresses regardless of any change in their role (primary or secondary).:
- The IP address assignment changes only when a FortiGate leaves or joins cluster.
Question 3
Question
Heartbeat communication can be enabled for physical interfaces, but not for: (Select 5)
Answer
-
VLAN subinterfaces
-
lPsec VPN interfaces
-
redundant interfaces
-
802.3ad aggregate interfaces
-
FortiGate switch ports
-
Software switch interfaces
-
InterVDOM link interfaces
Question 4
Question
As a best practice, in the moment a cluster is up and running and all interfaces are connected is recommended enabling interface monitoring. A monitored interface can easily become disconnected during initial setup and cause failovers to occur before the cluster is fully configured and tested.
Question 5
Question
Incremental synchronization:
After the initial synchronization is complete, the primary will send any further configuration changes done by an administrator to all the secondaries. For example, if you create a firewall address object, the primary doesn't resend its complete configuration, it sends just the new object.
Question 6
Question
When a new FortiGate is added to the cluster, the primary FortiGate compares its configuration checksum with the new secondary FortiGate configuration checksum. If the checksums don't match, the primary FortiGate uploads its complete configuration to the secondary FortiGate.
Question 7
Question
Types of HA sync
Question 8
Question
How many second check the cluster that all devices are synchronized:
Question 9
Question
If any secondary is out of sync, the checksum of secondary devices is then checked every
Answer
-
15 seconds.
-
60 seconds.
-
5 seconds.
Question 10
Question
If checksums don't match for five consecutive checks:
Question 11
Question
Not all the configuration settings are synchronized. There are a few that are not, such as:
- The system interface settings of the HA reserved management interface and the HA default route for the reserved management interface
- In-band HA management interface
- HA override
- HA device priority
- The virtual cluster priority
- The FortiGate host name
- The HA priority setting for a ping server (or dead gateway detection) configuration
- Licenses
- Caches
Question 12
Question
Session synchronization:
The synchronization of SSL VPN sessions is supported.
Question 13
Question
Session synchronization (Select 4)
Answer
-
TCP Session
-
IPsec VPN session
-
UDP and ICMP session
-
Multicast session
-
SSL VPN session
-
HA session
-
FGCP session
Question 14
Question
What information is synchronized between two FortiGate devices that belong to the same HA cluster?
Question 15
Question
Which one of the following session types can be synchronized in an HA cluster?
Answer
-
a. SSL VPN sessions
-
b. IPsec VPN sessions
Question 16
Question
[blank_start]A device failover[blank_end] is basically triggered when the primary FortiGate stops sending heartbeat traffic. When this happens, the secondaries renegotiate a new primary.
[blank_start]A link failover[blank_end] occurs when the link status of a monitored interface on the primary FortiGate goes down. You can configure an HA cluster to monitor the link status of some interfaces. If a monitored interface on the primary FortiGate is unplugged, or its link status goes down, a new primary FortiGate is elected.
Answer
-
A device failover
-
A link failover
Question 17
Question
Virtual MAC Addresses and Failover
Answer
-
On the primary, each interface is assigned a virtual MAC address.
HA heartbeat interfaces are not assigned a virtual MAC address.
Upon failover, the newly elected primary adopts the same virtual MAC addresses as the former primary.
-
On the primary, only one interface is assigned a virtual MAC address.
HA heartbeat interfaces have a assigned virtual MAC address.
Upon failover, the newly elected primary adopts a new virtual MAC addresses as the former primary.
Question 18
Question
You can configure virtual clustering between with two or more FortiGate´s devices with multiple VDOMs.
Question 19
Question
A HA failover occurs when the link status of a monitored interface on the goes down.
Answer
-
a. primary FortiGate
-
b. secondary FortiGate
Question 20
Question
The heartbeat interface IP address 169.254.0.1 is assigned to which FortiGate in an HA cluster?
Question 21
Question
Which of the following statements about the firmware upgrade process on an HA cluster is true?