nerdexam
Fortinet

FCSS_CDS_AR-7.6 · Question #8

Refer to the exhibit. You deployed an HA active-active load balance sandwich with two FortiGate VMs in Microsoft Azure. After the deployment, you prefer to use FGSP to synchronize sessions and allow…

The correct answer is A. The opposite FortiGate port 2 IP address. In an FGSP (FortiGate Session Life Support Protocol) deployment with asymmetric traffic in Azure, the peerip must be set to the opposite FortiGate's internal interface (port2) IP address. This ensures session synchronization between FortiGates through the internal network…

FortiGate-VM Architectures in Azure

Question

Refer to the exhibit. You deployed an HA active-active load balance sandwich with two FortiGate VMs in Microsoft Azure. After the deployment, you prefer to use FGSP to synchronize sessions and allow asymmetric return traffic. In the environment, FortiGate port 1 and port 2 are facing external and internal load balancers respectively. What IP address must you use in the peering configuration?

Exhibit

FCSS_CDS_AR-7.6 question #8 exhibit

Options

  • AThe opposite FortiGate port 2 IP address.
  • BThe public load balancer port 2 IP address.
  • CThe internal load balancer port 1 IP address.
  • DThe opposite FortiGate port 1 IP address.

How the community answered

(54 responses)
  • A
    61% (33)
  • B
    24% (13)
  • C
    9% (5)
  • D
    6% (3)

Explanation

In an FGSP (FortiGate Session Life Support Protocol) deployment with asymmetric traffic in Azure, the peerip must be set to the opposite FortiGate's internal interface (port2) IP address. This ensures session synchronization between FortiGates through the internal network (behind the internal load balancer), which is required for proper failover handling.

Topics

#FGSP#HA active-active#Azure load balancer sandwich#session synchronization

Community Discussion

No community discussion yet for this question.

Full FCSS_CDS_AR-7.6 Practice