FCSS_CDS_AR-7.6 · Question #61
Refer to the exhibit. You are troubleshooting a FortiGate HA floating IP issue with Microsoft Azure. After the failover, the new primary device does not have the previous primary device floating IP…
The correct answer is C. The Azure service principal account must have a contributor role. The debug output shows an AuthorizationFailed (403) error when FortiGate tries to update the Azure public IP. This indicates the Azure service principal account used by FortiGate does not have sufficient permissions. To manage floating IPs in HA, the service principal must be…
Question
Refer to the exhibit. You are troubleshooting a FortiGate HA floating IP issue with Microsoft Azure. After the failover, the new primary device does not have the previous primary device floating IP address. What could be the possible issue with this scenario?
Exhibit
Options
- AFortiGate port4 does not have internet access.
- BA wrong client secret credential is used.
- CThe Azure service principal account must have a contributor role.
- DThe error is caused by credential time expiration.
How the community answered
(47 responses)- A15% (7)
- B2% (1)
- C74% (35)
- D9% (4)
Explanation
The debug output shows an AuthorizationFailed (403) error when FortiGate tries to update the Azure public IP. This indicates the Azure service principal account used by FortiGate does not have sufficient permissions. To manage floating IPs in HA, the service principal must be assigned at least the Contributor role on the subscription or resource group.
Topics
Community Discussion
No community discussion yet for this question.
