nerdexam
Fortinet

NSE7_CDS_AR-7.6 · Question #61

Refer to the exhibit. You are troubleshooting a FortiGate HA floating IP issue with Microsoft Azure. After the failover, the new primary device does not have the previous primary device floating IP…

The correct answer is C. The Azure service principal account must have a contributor role. The debug output shows an AuthorizationFailed (403) error when FortiGate tries to update the Azure public IP. This indicates the Azure service principal account used by FortiGate does not have sufficient permissions. To manage floating IPs in HA, the service principal must be…

Troubleshooting and Optimization

Question

Refer to the exhibit. You are troubleshooting a FortiGate HA floating IP issue with Microsoft Azure. After the failover, the new primary device does not have the previous primary device floating IP address. What could be the possible issue with this scenario?

Exhibit

NSE7_CDS_AR-7.6 question #61 exhibit

Options

  • AFortiGate port4 does not have internet access.
  • BA wrong client secret credential is used.
  • CThe Azure service principal account must have a contributor role.
  • DThe error is caused by credential time expiration.

How the community answered

(55 responses)
  • A
    7% (4)
  • B
    15% (8)
  • C
    75% (41)
  • D
    4% (2)

Explanation

The debug output shows an AuthorizationFailed (403) error when FortiGate tries to update the Azure public IP. This indicates the Azure service principal account used by FortiGate does not have sufficient permissions. To manage floating IPs in HA, the service principal must be assigned at least the Contributor role on the subscription or resource group.

Topics

#Azure SDN connector#HA failover#service principal#floating IP

Community Discussion

No community discussion yet for this question.

Full NSE7_CDS_AR-7.6 Practice