FCSS_EFW_AD-7.4 · Question #22
An administrator is checking an enterprise network and sees a suspicious packet with the MAC address e0:23:ff:fc:00:86. What two conclusions can the administrator draw? (Choose two.)
The correct answer is A. The suspicious packet is related to a cluster that has VDOMs enabled. C. The suspicious packet is related to a cluster with a group-id value lower than 255. The MAC address e0:23:ff:fc:00:86 follows the format used in FortiGate High Availability (HA) clusters. When FortiGate devices are in an HA configuration, they use virtual MAC addresses for failover and redundancy purposes. The suspicious packet is related to a cluster that has…
Question
An administrator is checking an enterprise network and sees a suspicious packet with the MAC address e0:23:ff:fc:00:86. What two conclusions can the administrator draw? (Choose two.)
Options
- AThe suspicious packet is related to a cluster that has VDOMs enabled.
- BThe network includes FortiGate devices configured with the FGSP protocol.
- CThe suspicious packet is related to a cluster with a group-id value lower than 255.
- DThe suspicious packet corresponds to port 7 on a FortiGate device.
How the community answered
(49 responses)- A82% (40)
- B10% (5)
- D8% (4)
Explanation
The MAC address e0:23:ff:fc:00:86 follows the format used in FortiGate High Availability (HA) clusters. When FortiGate devices are in an HA configuration, they use virtual MAC addresses for failover and redundancy purposes. The suspicious packet is related to a cluster that has VDOMs enabled: FortiGate devices with Virtual Domains (VDOMs) enabled use specific MAC address ranges to differentiate HA-related traffic. This MAC address is likely part of that mechanism. The suspicious packet is related to a cluster with a group-id value lower than 255: FortiGate HA clusters assign virtual MAC addresses based on the group ID. The last octet (00:86) corresponds to a group ID that is below 255, confirming this option.
Topics
Community Discussion
No community discussion yet for this question.