nerdexam
Fortinet

NSE7_PBC-7.2 · Question #63

Refer to the exhibit. You are troubleshooting a FortiGate HA floating IP issue with Microsoft Azure. After the failover, the new primary device does not have the previous primary device floating IP…

The correct answer is D. The Azure service principle account must have a contributor role. In this scenario, the issue is caused by the Azure service principle account not having a contributor role. This is required for the FortiGate HA floating IP to work properly. Without this role, the new primary device will not have the previous primary device floating IP…

FortiGate-VM in Public Cloud

Question

Refer to the exhibit. You are troubleshooting a FortiGate HA floating IP issue with Microsoft Azure. After the failover, the new primary device does not have the previous primary device floating IP address. What could be the possible issue With this scenario?

Exhibit

NSE7_PBC-7.2 question #63 exhibit

Options

  • AFortiGate port4 does not have internet access.
  • BA wrong client secret credential is used
  • CThe error is caused by credential time expiration.
  • DThe Azure service principle account must have a contributor role.

How the community answered

(57 responses)
  • A
    7% (4)
  • B
    4% (2)
  • C
    18% (10)
  • D
    72% (41)

Explanation

In this scenario, the issue is caused by the Azure service principle account not having a contributor role. This is required for the FortiGate HA floating IP to work properly. Without this role, the new primary device will not have the previous primary device floating IP address after

Topics

#Azure HA failover#floating IP#service principal#contributor role

Community Discussion

No community discussion yet for this question.

Full NSE7_PBC-7.2 Practice