ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 46 - NSE7_PBC-7.2 discussion

Report
Export

Refer to the exhibit.

You deployed an HA active-active load balance sandwich with two FortiGate VMs in Microsoft Azure.

After the deployment, you prefer to use FGSP to synchronize sessions, and allow asymmetric return traffic In the environment, FortiGate port 1 and port 2 are facing external and internal load balancers respectively

What IP address must you use in the peerip configuration?

A.
The opposite FortiGate port 1 IP address.
Answers
A.
The opposite FortiGate port 1 IP address.
B.
The public load balancer port 2 IP address
Answers
B.
The public load balancer port 2 IP address
C.
The internal load balancer port 1 IP address.
Answers
C.
The internal load balancer port 1 IP address.
D.
The opposite FortiGate port 2 IP address.
Answers
D.
The opposite FortiGate port 2 IP address.
Suggested answer: D

Explanation:

In an HA active-active load balance configuration with FortiGate VMs, especially in Microsoft Azure where FGSP (FortiGate Session Life Support Protocol) is used for session synchronization, the correct configuration for the peerip is:

D) The opposite FortiGate port 2 IP address.

HA Synchronization Requirements: FGSP requires direct communication between the FortiGates to synchronize the session table. This synchronization typically occurs over a dedicated HA link that connects the HA pair.

Asymmetric Traffic Considerations: FGSP allows asymmetric traffic to rejoin the correct session by synchronizing session information, including NAT and TCP sequence tracking between the FortiGate units in a cluster.

Configuration Specifics: For port 2, which is facing the internal load balancer, the peerip should be set to the corresponding port 2 IP address of the opposite FortiGate. This allows the internal interfaces to communicate directly with each other for session synchronization purposes, which is crucial in an active-active deployment to ensure sessions persist during failover scenarios.

asked 18/09/2024
Ralitsa Yankova
50 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first