nerdexam
Fortinet

NSE7_CDS_AR-7.6 · Question #8

Refer to the exhibit. You deployed an HA active-active load balance sandwich with two FortiGate VMs in Microsoft Azure. After the deployment, you prefer to use FGSP to synchronize sessions and allow…

The correct answer is A. The opposite FortiGate port 2 IP address. In an FGSP (FortiGate Session Life Support Protocol) deployment with asymmetric traffic in Azure, the peerip must be set to the opposite FortiGate's internal interface (port2) IP address. This ensures session synchronization between FortiGates through the internal network…

Deployment and Integration of Fortinet Cloud Solutions

Question

Refer to the exhibit. You deployed an HA active-active load balance sandwich with two FortiGate VMs in Microsoft Azure. After the deployment, you prefer to use FGSP to synchronize sessions and allow asymmetric return traffic. In the environment, FortiGate port 1 and port 2 are facing external and internal load balancers respectively. What IP address must you use in the peering configuration?

Exhibit

NSE7_CDS_AR-7.6 question #8 exhibit

Options

  • AThe opposite FortiGate port 2 IP address.
  • BThe public load balancer port 2 IP address.
  • CThe internal load balancer port 1 IP address.
  • DThe opposite FortiGate port 1 IP address.

How the community answered

(32 responses)
  • A
    66% (21)
  • B
    22% (7)
  • C
    3% (1)
  • D
    9% (3)

Explanation

In an FGSP (FortiGate Session Life Support Protocol) deployment with asymmetric traffic in Azure, the peerip must be set to the opposite FortiGate's internal interface (port2) IP address. This ensures session synchronization between FortiGates through the internal network (behind the internal load balancer), which is required for proper failover handling.

Topics

#FGSP#Azure active-active HA#load balancer sandwich#session synchronization

Community Discussion

No community discussion yet for this question.

Full NSE7_CDS_AR-7.6 Practice