High Availability Flashcards

1
Q

How many FTG’s can be put in a cluster?

A

two to four

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What is synchronized in an HA Cluster?

A

Configruation, session info, FIB entries, FortiGuard definitions,

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Do passive members in a A-P HA cluster process traffic?

A

No, only start forwarding in the event of a fail over.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

How does active-active work?

A

The primary FTG can distribute sessions to other cluster members

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is FGCP?

A

FortiGate Clustering Protocol

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What does FGCP do?

A

Used for member discovery, primary election, data sync, member health monitoring.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What is frame type 8890/1 in H/A Heartbeats

A

0x8890 is NAT mode 0x8891 is transparent mode

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What is frame type 8893 in H/A Heartbeats

A

Data synchronization, logging and cli management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

For HA what does inner packet type TCP/UDP 703 used for?

A

Data Sync

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

For HA what does inner packet type TCP 700 used for?

A

Logging and email alerts

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

For HA what does inner packet type TCP 22 used for?

A

CLI Management

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What can trigger an HA Failover

A

Dead member, Failed link, Failed remote link, high memory usage, failed SSD, admin triggered

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What must match in order to form an HA Cluster?

A

Firmware version,
Model (virtual or physical)
Licensing
Hard drive config (size, partitions)
Operating mode: NAT or transparent

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What happens if the licensing models are different in HA Clusters?

A

The lowest level of license in common is used.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What must match from an HA Settings perspective?

A

Group ID, group name, password and interface settings

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

Should you place all heart beat interfaces in the same broadcast domain?

A

Yes

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
17
Q

What is the Election process when override is disabled

A

of connected interfaces
HA Uptime
Priority (highest)
Lowest serial number

18
Q

what does diagnose sys ha reset-uptime do?

A

Reset HA uptime to 0]

19
Q

What is the primary fortunate election with override enabled?

A

of connected interfaces
Priority (highest)
HA Uptime
Lowest serial number

The highest priority means you can specify a FTG that will always become the primary even after it recovers from a failover.

20
Q

What operational data does the primary FTG synch

A

Some config settings
FIB entries
DHCP lease
ARP table
FortiGuard definitions
IPsec SA’s
Sessions (must be enabled)

21
Q

What is the heartbeat IP address assignment for the highest serial number? second?

A

169.254.0.1 for first
169.254.0.2 for the second

22
Q

When do heartbeat IP address change?

A

When a device joins or leaves the cluster

23
Q

What port must you use for heartbeats?

A

physical only

24
Q

Are heartbeat interfaces used for user traffic?

A

no

25
Q

What is a monitored interface?

A

An interface that is monitored to determine a failure has occurred and to failover to the other unit.

26
Q

What are examples of incremental sync in HA

A

DHCP leases
FIB entries
IPSec SAs
Session info

27
Q

What happens if checksums don’t match in a HA cluster?

A

After five attempts the secondary downloads the full configuration from the primary.

28
Q

What are settings are not synced between HA devices>

A

HA interface settings
HA override
HA device priority
HA virtual cluster priority
FTG hostname
ping sever
Licenses
Cache

29
Q

Does FTG keep track of Multicast sessions for HA?

A

No just multicast routes

30
Q

What is the recommended TTL timer for multicast routes to stay in the HA table?

A

120 seconds recommended.

31
Q

Is link HA priority synchronized to all members?

A

No it is locally significant only.

32
Q

How do you prevent MAC address conflicts with multiple HA clusters in the same broadcast domain?

A

Assign different HA group IDs

33
Q

How does the new primary let the network know it can reach the virtual Mac addresses through new ports?

A

Gratuitous ARPs

34
Q

Does the Primary HA Fortigate resign traffic sessions when a secondary fails?

A

Yes

35
Q

What command enables distribution of all traffic for an HA cluster?

A

under HA settings type load-balance-all

36
Q

Does the Primary FTG always receive the packets from clients in an Active-Active (proxy-based) HA cluster?

A

Yes

37
Q

What sessions cannot be load balanced for HA

A

ICMP, Multicast, broad cast, SIP SLG, IM, P@P and IPsec VPN SSL and WCCP

38
Q

When are HTTPS sessions not load balanced in an Active-Active deployment?

A

if subjected to proxy based HTTPS inspection

39
Q

When are HTTPS sessions load balanced in active-active HA cluster

A

Load-balance-all is enabled
and
flow mode inspection
or
proxy mode is enabled but HTTPS traffic is not enabled.

40
Q

What is the default A/A Load balancing methods?

A

weight-round-robin the higher the weight the more sessions

41
Q

What is the variable order for the set weight command

A

<id> <weight)
</id>

42
Q
A