NSE4 · Question #460
Two FortiGate units with NP6 processors form an active-active cluster. The cluster is doing security profile (UTM) inspection over all the user traffic. What statements are true regarding the…
The correct answer is B. They are not offloaded to the NP6 in the master unit. C. They are offloaded to the NP6 in the slave unit. In an active-active FortiGate cluster, sessions offloaded from the master unit for security profile inspection are processed by the NP6 processor on the slave unit, thereby not utilizing the master unit's NP6 for these specific sessions.
Question
Two FortiGate units with NP6 processors form an active-active cluster. The cluster is doing security profile (UTM) inspection over all the user traffic. What statements are true regarding the sessions that the master unit is offloading to the slave unit for inspection? (Choose two.)
Options
- AThey are offloaded to the NP6 in the master unit.
- BThey are not offloaded to the NP6 in the master unit.
- CThey are offloaded to the NP6 in the slave unit.
- DThey are not offloaded to the NP6 in the slave unit.
How the community answered
(58 responses)- A10% (6)
- B84% (49)
- D5% (3)
Why each option
In an active-active FortiGate cluster, sessions offloaded from the master unit for security profile inspection are processed by the NP6 processor on the slave unit, thereby not utilizing the master unit's NP6 for these specific sessions.
Sessions offloaded from the master to a slave unit are specifically moved to leverage the slave's resources, meaning they are not processed by the master unit's NP6.
In an active-active cluster with sessions offloaded from the master to a slave for security inspection, the master unit's NP6 processors are not used for these specific offloaded sessions, as the processing is shifted to the slave unit.
When the master unit offloads sessions for security profile (UTM) inspection to a slave unit in an active-active cluster, the NP6 processors of the slave unit handle the hardware acceleration for those offloaded sessions. This distributes the processing load across both units.
The purpose of offloading sessions to the slave unit is to utilize its NP6 processors for hardware acceleration and security inspection, so stating they are not offloaded to the slave's NP6 contradicts the principle of load distribution.
Concept tested: FortiGate active-active HA and NP6 offloading
Source: https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/469443/ha-and-session-processing
Topics
Community Discussion
No community discussion yet for this question.