NSE4 · Question #70
Two FortiGate units with NP6 processors form an active-active cluster. The cluster is doing security profile (UTM) inspection over all the user traffic. What statements are true regarding the…
The correct answer is A. They are accelerated by hardware in the master unit. D. They are not accelerated by hardware in the slave unit. This question describes hardware acceleration behavior in an active-active FortiGate cluster with NP6 processors when UTM inspection is performed and sessions are offloaded between units.
Question
Two FortiGate units with NP6 processors form an active-active cluster. The cluster is doing security profile (UTM) inspection over all the user traffic. What statements are true regarding the sessions that the master unit is offloading to the slave unit for inspection? (Choose two.)
Options
- AThey are accelerated by hardware in the master unit.
- BThey are not accelerated by hardware in the master unit.
- CThey are accelerated by hardware in the slave unit.
- DThey are not accelerated by hardware in the slave unit.
How the community answered
(71 responses)- A62% (44)
- B27% (19)
- C11% (8)
Why each option
This question describes hardware acceleration behavior in an active-active FortiGate cluster with NP6 processors when UTM inspection is performed and sessions are offloaded between units.
If the master unit initially processes the traffic before offloading it to the slave for inspection, its NP6 processor can still accelerate initial packet processing, session setup, and basic forwarding or NAT operations on its segment of the flow.
Even if deep inspection is offloaded, the master unit's NP6 can still accelerate initial traffic handling and session establishment tasks before passing the session to the slave for inspection.
Since UTM inspection is being performed, the slave unit's NP6 processor generally cannot accelerate the deep packet inspection process itself, which relies on the CPU or a dedicated CP processor.
When UTM (security profile) inspection is applied, it typically requires deep packet analysis by the CPU or a dedicated content processor (CP), preventing full hardware acceleration by the NP6 on the slave unit during the inspection phase.
Concept tested: FortiGate active-active HA, NP6 hardware acceleration, UTM inspection
Source: https://docs.fortinet.com/document/fortigate/7.4.0/hardware-acceleration/258597/np6-offloading-capabilities
Topics
Community Discussion
No community discussion yet for this question.