nerdexam
Fortinet

FCSS_CDS_AR-7.6 · Question #61

Refer to the exhibit. You are troubleshooting a FortiGate HA floating IP issue with Microsoft Azure. After the failover, the new primary device does not have the previous primary device floating IP…

The correct answer is C. The Azure service principal account must have a contributor role. The debug output shows an AuthorizationFailed (403) error when FortiGate tries to update the Azure public IP. This indicates the Azure service principal account used by FortiGate does not have sufficient permissions. To manage floating IPs in HA, the service principal must be…

FortiGate-VM Architectures in Azure

Question

Refer to the exhibit. You are troubleshooting a FortiGate HA floating IP issue with Microsoft Azure. After the failover, the new primary device does not have the previous primary device floating IP address. What could be the possible issue with this scenario?

Exhibit

FCSS_CDS_AR-7.6 question #61 exhibit

Options

  • AFortiGate port4 does not have internet access.
  • BA wrong client secret credential is used.
  • CThe Azure service principal account must have a contributor role.
  • DThe error is caused by credential time expiration.

How the community answered

(47 responses)
  • A
    15% (7)
  • B
    2% (1)
  • C
    74% (35)
  • D
    9% (4)

Explanation

The debug output shows an AuthorizationFailed (403) error when FortiGate tries to update the Azure public IP. This indicates the Azure service principal account used by FortiGate does not have sufficient permissions. To manage floating IPs in HA, the service principal must be assigned at least the Contributor role on the subscription or resource group.

Topics

#HA failover#floating IP#Azure service principal#SDN connector

Community Discussion

No community discussion yet for this question.

Full FCSS_CDS_AR-7.6 Practice