nerdexam
Fortinet

NSE7_PBC-7.2 · Question #9

You need to deploy FortiGate VM devices in a highly available topology in the Microsoft Azure cloud. The following are the requirements of your deployment: - Two FortiGate devices must be deployed…

The correct answer is B. config system ha. FTG HA Active/Active requires the following configuration to sync the session by FGSP config system ha set session-pickup enable set session-pickup-connectionless enable set session-pickup-nat enable set session-pickup-expectation enable set override disable config system…

FortiGate-VM in Public Cloud

Question

You need to deploy FortiGate VM devices in a highly available topology in the Microsoft Azure cloud. The following are the requirements of your deployment:

  • Two FortiGate devices must be deployed; each in a different availability zone.
  • Each FortiGate requires two virtual network interfaces: one will connect to a public subnet and

the other will connect to a private subnet.

  • An external Microsoft Azure load balancer will distribute ingress traffic to both FortiGate devices

in an active- active topology.

  • An internal Microsoft Azure load balancer will distribute egress traffic from protected virtual

machines to both FortiGate devices in an active-active topology.

  • Traffic should be accepted or denied by a firewall policy in the same way by either FortiGate

device in this topology. Which FortiOS CLI configuration can help reduce the administrative effort required to maintain the FortiGate devices, by synchronizing firewall policy and object configuration between the FortiGate devices?

Options

  • Aconfig system sdn-connector
  • Bconfig system ha
  • Cconfig system auto-scale
  • Dconfig system session-sync

How the community answered

(30 responses)
  • A
    7% (2)
  • B
    73% (22)
  • C
    3% (1)
  • D
    17% (5)

Explanation

FTG HA Active/Active requires the following configuration to sync the session by FGSP config system ha set session-pickup enable set session-pickup-connectionless enable set session-pickup-nat enable set session-pickup-expectation enable set override disable config system cluster-sync set peerip 10.0.1.x set syncvd "root"

Topics

#active-active HA#Azure load balancer#availability zones#auto-scale config

Community Discussion

No community discussion yet for this question.

Full NSE7_PBC-7.2 Practice