High Availability Flashcards

1
Q

What does FortiGate use to discover members, elect the primary FortiGate, and monitor the health of members?

A

FortiGate Clustering Protocol (FGCP)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the two HA operation modes?

A
  • Active-active
  • Active-passive
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

In active-passive mode, how does the secondary FortiGate device behave?

A
  • Passive, monitors the status of the primary device
  • Takes over primary role if a problem is detected on the primary FortiGate
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What is the difference between active-passive mode and active-active mode?

A
  • In active-active, all cluster members can process traffic
  • The primary FortiGate can distribute supported sessions to the secondary devices
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What are the requirements to form an HA cluster?

A
  • Members must have the same
  • Model
  • Firmware version
  • Licensing (if different, uses the lower)
  • Hard drive configuration
  • Operating mode
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What settings should you configure the same on each HA cluster member?

A
  • Group ID
  • Group name
  • Password
  • Heartbeat interface settings
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are some best practices to apply when configuring HA clusters?

A
  • Configure at least two heartbeat interfaces for redundancy
  • Try to place all heartbeat interfaces in the same broadcast domain, or directly connected if only two
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

How does the primary FortiGate election process work?

A
  • Compares number of monitored interfaces that are up
  • Compares HA uptime of each member
  • Highest priority
  • Highest serial number
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What happens when HA override is disabled?

A
  • HA uptime has precedence over the priority setting
  • If you must manually fail over to a secondary device, you can do so by reducing the HA uptime of the primary FortiGate by running diagnose sys ha reset-uptime
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What is a task the primary FortiGate takes on only in active-active mode?

A

Distributes sessions to secondary members

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What is a task performed by the secondary FortiGate only in active-active mode?

A

Processes traffic distributed by the primary

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

How does FGCP assign heartbeat IP addresses?

A
  • Automatically based on the serial number of each device
  • 169.254.0.1 gets assigned to the device with the highest SN
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What are characteristics of heartbeat IP addresse?

A
  • Non-routable
  • Only used for FGCP operations
  • HA cluster uses them to distinguish cluster members and synchronize data
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

What is good practice when configuring heartbeat interfaces?

A
  • Must configure at least one port as a heartbeat interface, and can only use physical interfaces
  • Heartbeat traffic should be on a dedicated VLAN
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What must be configured for link failover to work?

A

One or more monitored interfaces

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

How does FortiGate prepare for a failover?

A
  • HA cluster keeps its configurations in sync
  • Checks every 60 seconds
17
Q

What does the primary FortiGate automatically synchronize with VPNs?

A
  • IPsec data, tunnels continue to be up after failover
  • Not SSL VPN data, tunnel must be restarted after a failover
18
Q

What’s memory based failover?

A

HA failover is triggered when the memory utilization on the primary FortiGate reaches the configured threshold

19
Q

What happens in terms of virtual MAC address after a failover?

A

The newly elected primary adopts the same virtual MAC address as the former primary

20
Q

What’s the point of a full mesh HA topology?

A

To eliminate a single point of failure

21
Q

Which session type can you synchronize in an HA cluster?

A

Non-proxy TCP sessions

22
Q

How would you upgrade firmware in an HA cluster?

A

Upload the new firmware to the primary FortiGate only