Pregunta 1
Pregunta
The cluster assigns virtual IP addresses to heartbeat interfaces based on each FortiGate’s serial number, what subnet use?
Respuesta
-
169.254.0.0
-
254.169.0.0
-
169.0.254.0
-
254.0.169.0
Pregunta 2
Pregunta
FortiGates keep their heartbeat virtual IP addresses regardless of any change in their role (primary or secondary).:
- The IP address assignment changes only when a FortiGate leaves or joins cluster.
Pregunta 3
Pregunta
Heartbeat communication can be enabled for physical interfaces, but not for: (Select 5)
Respuesta
-
VLAN subinterfaces
-
lPsec VPN interfaces
-
redundant interfaces
-
802.3ad aggregate interfaces
-
FortiGate switch ports
-
Software switch interfaces
-
InterVDOM link interfaces
Pregunta 4
Pregunta
As a best practice, in the moment a cluster is up and running and all interfaces are connected is recommended enabling interface monitoring. A monitored interface can easily become disconnected during initial setup and cause failovers to occur before the cluster is fully configured and tested.
Pregunta 5
Pregunta
Incremental synchronization:
After the initial synchronization is complete, the primary will send any further configuration changes done by an administrator to all the secondaries. For example, if you create a firewall address object, the primary doesn't resend its complete configuration, it sends just the new object.
Pregunta 6
Pregunta
When a new FortiGate is added to the cluster, the primary FortiGate compares its configuration checksum with the new secondary FortiGate configuration checksum. If the checksums don't match, the primary FortiGate uploads its complete configuration to the secondary FortiGate.
Pregunta 7
Pregunta
Types of HA sync
Pregunta 8
Pregunta
How many second check the cluster that all devices are synchronized:
Pregunta 9
Pregunta
If any secondary is out of sync, the checksum of secondary devices is then checked every
Respuesta
-
15 seconds.
-
60 seconds.
-
5 seconds.
Pregunta 10
Pregunta
If checksums don't match for five consecutive checks:
Pregunta 11
Pregunta
Not all the configuration settings are synchronized. There are a few that are not, such as:
- The system interface settings of the HA reserved management interface and the HA default route for the reserved management interface
- In-band HA management interface
- HA override
- HA device priority
- The virtual cluster priority
- The FortiGate host name
- The HA priority setting for a ping server (or dead gateway detection) configuration
- Licenses
- Caches
Pregunta 12
Pregunta
Session synchronization:
The synchronization of SSL VPN sessions is supported.
Pregunta 13
Pregunta
Session synchronization (Select 4)
Respuesta
-
TCP Session
-
IPsec VPN session
-
UDP and ICMP session
-
Multicast session
-
SSL VPN session
-
HA session
-
FGCP session
Pregunta 14
Pregunta
What information is synchronized between two FortiGate devices that belong to the same HA cluster?
Pregunta 15
Pregunta
Which one of the following session types can be synchronized in an HA cluster?
Respuesta
-
a. SSL VPN sessions
-
b. IPsec VPN sessions
Pregunta 16
Pregunta
[blank_start]A device failover[blank_end] is basically triggered when the primary FortiGate stops sending heartbeat traffic. When this happens, the secondaries renegotiate a new primary.
[blank_start]A link failover[blank_end] occurs when the link status of a monitored interface on the primary FortiGate goes down. You can configure an HA cluster to monitor the link status of some interfaces. If a monitored interface on the primary FortiGate is unplugged, or its link status goes down, a new primary FortiGate is elected.
Respuesta
-
A device failover
-
A link failover
Pregunta 17
Pregunta
Virtual MAC Addresses and Failover
Respuesta
-
On the primary, each interface is assigned a virtual MAC address.
HA heartbeat interfaces are not assigned a virtual MAC address.
Upon failover, the newly elected primary adopts the same virtual MAC addresses as the former primary.
-
On the primary, only one interface is assigned a virtual MAC address.
HA heartbeat interfaces have a assigned virtual MAC address.
Upon failover, the newly elected primary adopts a new virtual MAC addresses as the former primary.
Pregunta 18
Pregunta
You can configure virtual clustering between with two or more FortiGate´s devices with multiple VDOMs.
Pregunta 19
Pregunta
A HA failover occurs when the link status of a monitored interface on the goes down.
Respuesta
-
a. primary FortiGate
-
b. secondary FortiGate
Pregunta 20
Pregunta
The heartbeat interface IP address 169.254.0.1 is assigned to which FortiGate in an HA cluster?
Pregunta 21
Pregunta
Which of the following statements about the firmware upgrade process on an HA cluster is true?