exam questions

Exam NSE4_FGT-7.2 All Questions

View all questions & answers for the NSE4_FGT-7.2 exam

Exam NSE4_FGT-7.2 topic 1 question 27 discussion

Actual exam question from Fortinet's NSE4_FGT-7.2
Question #: 27
Topic #: 1
[All NSE4_FGT-7.2 Questions]

Refer to the exhibits.
Exhibit A shows a topology for a FortiGate HA cluster that performs proxy-based inspection on traffic. Exhibit B shows the HA configuration and the partial output of the get system ha status command.


Based on the exhibits, which two statements about the traffic passing through the cluster are true? (Choose two.)

  • A. For non-load balanced connections, packets forwarded by the cluster to the server contain the virtual MAC address of port2 as source.
  • B. The traffic sourced from the client and destined to the server is sent to FGT-1.
  • C. The cluster can load balance ICMP connections to the secondary.
  • D. For load balanced connections, the primary encapsulates TCP SYN packets before forwarding them to the secondary.
Show Suggested Answer Hide Answer
Suggested Answer: AD 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
BoostBoris
Highly Voted 1 year, 11 months ago
Selected Answer: AD
A: Non load balance: traffic enters port1 and go out port2 from FGT1. FGT2 is in standby mode D: In proxy inspection mode, SYN packet goes to FGT1 port1. It is then forwarded to FGT2. the source MAC address of the packet is changed to the physical MAC address of port1 on the primary and the destination MAC address to the physical MAC address of port1 on the secondary. This is also known as MAC address rewrite. In addition, the primary encapsulates the packet in an Ethernet frame type 0x8891. The encapsulation is done only for the first packet of a load balanced session
upvoted 10 times
BoostBoris
1 year, 10 months ago
Sorry, FGT2 is primary... So the other way around --'
upvoted 9 times
...
...
walter_rcp
Highly Voted 1 year, 11 months ago
D: is the only correct for me.
upvoted 7 times
...
vuhidus
Most Recent 1 month, 3 weeks ago
Selected Answer: AD
A & D
upvoted 1 times
...
AMK2ENG
1 year ago
A. For non-load balanced connections, packets forwarded by the cluster to the server contain the virtual MAC address of port2 as source. D. For load balanced connections, the primary encapsulates TCP SYN packets before forwarding them to the secondary.
upvoted 1 times
...
Diego_Farani
1 year, 2 months ago
Selected Answer: AD
FortiGate Infrastructure 7.2 Study Guide (p.317 & p.320): "To forward traffic correctly, a FortiGate HA solution uses virtual MAC addresses." "The primary forwards the SYN packet to the selected secondary. (...) This is also known as MAC address rewrite. In addition, the primary encapsulates the packet in an Ethernet frame type 0x8891. The encapsulation is done only for the first packet of a load balanced session. The encapsulated packet includes the original packet plus session information that the secondary requires to process the traffic."
upvoted 3 times
...
Rian
1 year, 3 months ago
A and B. Since Secondary : FGT-1 HA Cluster index = 0
upvoted 1 times
...
Slash_JM
1 year, 3 months ago
Selected Answer: AD
FortiGate Infrastructure 7.2 Study Guide p.320-322
upvoted 2 times
...
raydel92
1 year, 4 months ago
Selected Answer: AD
Correct: A. For non-load balanced connections, packets forwarded by the cluster to the server contain the virtual MAC address of port2 as source. D. For load balanced connections, the primary encapsulates TCP SYN packets before forwarding them to the secondary. Incorrect: B. The traffic sourced from the client and destined to the server is sent to FGT-1. (not primary) C. The cluster can load balance ICMP connections to the secondary. (not enabled) FortiGate Infrastructure 7.2 Study Guide (p.317 & p.320): "To forward traffic correctly, a FortiGate HA solution uses virtual MAC addresses." "The primary forwards the SYN packet to the selected secondary. (...) This is also known as MAC address rewrite. In addition, the primary encapsulates the packet in an Ethernet frame type 0x8891. The encapsulation is done only for the first packet of a load balanced session. The encapsulated packet includes the original packet plus session information that the secondary requires to process the traffic." Reference and download study guide: https://ebin.pub/fortinet-fortigate-infrastructure-study-guide-for-fortios-72.html
upvoted 4 times
...
lucas09
1 year, 4 months ago
A and D for A-A loadbalance traffic from the client is received on the primary's Vmac to which the packet is then sent to the secondary for inspection with the physical mac address of the primary as source. Then it comes back to primary and client to which the handshake has begun.
upvoted 2 times
...
darkstar15
1 year, 5 months ago
La C no es por que se puede sincronizar pero no hacer balanceo de ICMP
upvoted 2 times
...
erawemk
1 year, 6 months ago
Selected Answer: D
A. Is not true, always Cluster sends traffic to server using physical MAC B. Is not true, the traffic sourced from the client and destined to the server is sent to FGT-2. C. Is not true, the cluster cannot load balance ICMP connections D. Is true for load balanced connections, the primary encapsulates TCP SYN packets before forwarding them to the secondary using 0x8891 frame Everything is taken from infrastruture study guide pages 320-322
upvoted 3 times
...
umairmasood
1 year, 6 months ago
Answer is A & D
upvoted 1 times
...
yamahaforti
1 year, 7 months ago
Can A really be correct? View the slide on page 322 FortiGate_Infrastructure_7.2_Study_Guide-Online.pdf It's shows secondary-physical MAC-port2 to server D is the only correct one
upvoted 2 times
...
ferdi1989
1 year, 7 months ago
in mode A-A no icmp protocol can ben load balanced
upvoted 2 times
...
Mturco
1 year, 10 months ago
Selected Answer: AD
correct answer is A&D
upvoted 2 times
...
danieldelgado
1 year, 10 months ago
Correct answers are C and D. The cluster is in Active-Active mode and FGT1 is the secondary
upvoted 4 times
...
shadow2020
1 year, 10 months ago
Set mode is a-a not a-p
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago