nerdexam
Fortinet

FCSS_CDS_AR-7.6 · Question #43

You have deployed a FortiGate HA cluster in Azure using a Gateway Load Balancer for traffic inspection. However, traffic is not being routed correctly through the firewalls. What can be the cause of…

The correct answer is A. The Fortinet VMs have IP forwarding disabled, which is required for traffic inspection. Azure requires IP forwarding enabled on each FortiGate NIC used for inspection; without it, Azure drops packets that the VM tries to route onward, so traffic won't traverse the HA firewalls.

FortiGate-VM Architectures in Azure

Question

You have deployed a FortiGate HA cluster in Azure using a Gateway Load Balancer for traffic inspection. However, traffic is not being routed correctly through the firewalls. What can be the cause of the issue?

Options

  • AThe Fortinet VMs have IP forwarding disabled, which is required for traffic inspection.
  • BThe health probes for the Gateway Load Balancer are failing, which causes traffic to bypass the
  • CThe Gateway Load Balancer is not associated with the correct network security group (NSG)
  • DThe protected VMs are in a different Azure subscription, which prevents the Gateway Load

How the community answered

(32 responses)
  • A
    75% (24)
  • B
    3% (1)
  • C
    16% (5)
  • D
    6% (2)

Explanation

Azure requires IP forwarding enabled on each FortiGate NIC used for inspection; without it, Azure drops packets that the VM tries to route onward, so traffic won't traverse the HA firewalls.

Topics

#Azure Gateway Load Balancer#FortiGate HA#IP forwarding#traffic inspection

Community Discussion

No community discussion yet for this question.

Full FCSS_CDS_AR-7.6 Practice