nerdexam
Fortinet

NSE4 · Question #460

Two FortiGate units with NP6 processors form an active-active cluster. The cluster is doing security profile (UTM) inspection over all the user traffic. What statements are true regarding the…

The correct answer is B. They are not offloaded to the NP6 in the master unit. C. They are offloaded to the NP6 in the slave unit. In an active-active FortiGate cluster, sessions offloaded from the master unit for security profile inspection are processed by the NP6 processor on the slave unit, thereby not utilizing the master unit's NP6 for these specific sessions.

Submitted by ashley.k· Apr 18, 2026Security Profiles and Content Inspection

Question

Two FortiGate units with NP6 processors form an active-active cluster. The cluster is doing security profile (UTM) inspection over all the user traffic. What statements are true regarding the sessions that the master unit is offloading to the slave unit for inspection? (Choose two.)

Options

  • AThey are offloaded to the NP6 in the master unit.
  • BThey are not offloaded to the NP6 in the master unit.
  • CThey are offloaded to the NP6 in the slave unit.
  • DThey are not offloaded to the NP6 in the slave unit.

How the community answered

(58 responses)
  • A
    10% (6)
  • B
    84% (49)
  • D
    5% (3)

Why each option

In an active-active FortiGate cluster, sessions offloaded from the master unit for security profile inspection are processed by the NP6 processor on the slave unit, thereby not utilizing the master unit's NP6 for these specific sessions.

AThey are offloaded to the NP6 in the master unit.

Sessions offloaded from the master to a slave unit are specifically moved to leverage the slave's resources, meaning they are not processed by the master unit's NP6.

BThey are not offloaded to the NP6 in the master unit.Correct

In an active-active cluster with sessions offloaded from the master to a slave for security inspection, the master unit's NP6 processors are not used for these specific offloaded sessions, as the processing is shifted to the slave unit.

CThey are offloaded to the NP6 in the slave unit.Correct

When the master unit offloads sessions for security profile (UTM) inspection to a slave unit in an active-active cluster, the NP6 processors of the slave unit handle the hardware acceleration for those offloaded sessions. This distributes the processing load across both units.

DThey are not offloaded to the NP6 in the slave unit.

The purpose of offloading sessions to the slave unit is to utilize its NP6 processors for hardware acceleration and security inspection, so stating they are not offloaded to the slave's NP6 contradicts the principle of load distribution.

Concept tested: FortiGate active-active HA and NP6 offloading

Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/469443/ha-and-session-processing

Topics

#FortiGate HA (Active-Active)#NP6 Processor#Security Profiles (UTM)#Hardware Acceleration

Community Discussion

No community discussion yet for this question.

Full NSE4 Practice