Courseiva

NSE4 High Availability and Diagnostics Practice Question

A company has two FortiGate units in an active-active HA cluster. They want to ensure that sessions initiated from the internet through a virtual IP are synchronized to the peer unit in case of failover. Which HA setting is required?

⚠ Common exam trap

NSE4 often tests the distinction between HA settings that sound related — candidates pick 'configure the same VIP on both units' because it seems logical, but VIP configuration is automatic in HA; the actual requirement is enabling session-pickup.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable 'session-pickup' under config system ha

In a FortiGate active-active HA cluster, session-pickup (also called session synchronization) must be enabled under 'config system ha' to ensure that sessions — including those initiated through a virtual IP from the internet — are synchronized to the peer unit. Without session-pickup, a failover would drop existing sessions because the new primary has no state for them. This is the specific HA setting that controls whether firewall sessions are mirrored across cluster members.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable 'set ha-mgmt-status enable' on the WAN interface

    Why it's wrong here

    The ha-mgmt-status setting on an interface designates that interface as a dedicated management connection to the HA cluster, typically using a special management IP. It does nothing to replicate the session table or stateful connection states between the two firewalls. Session synchronization is governed solely by the session-pickup parameter in the system HA configuration, so enabling HA management status cannot satisfy the requirement of preserving established VIP sessions after a failover.

  • ✗

    Set 'set schedule' to 'round-robin' for the VIP

    Why it's wrong here

    VIP objects in FortiOS do not have a 'set schedule' parameter; the 'schedule' key appears only for load balancing pools and policies or for the round-robin distribution among multiple real servers in a virtual server pool. Setting round-robin would only affect load distribution, not the HA stateful session sync mechanism. Furthermore, session ownership and connection tracking are handled by the kernel session table, not by VIP configuration, and session-pickup is the only parameter that makes sessions fault-tolerant across HA members.

  • ✗

    Configure the same virtual IP on both units

    Why it's wrong here

    In an HA cluster, configuration is automatically synchronized from the primary unit to the backup units, so manually defining the same VIP on each unit is unnecessary and can even cause configuration conflicts if the primary already manages that VIP. Even if a VIP is present on both units, the firewall does not automatically copy the runtime session table to the peer; session state replication requires explicit session-pickup in the HA settings. Therefore, merely matching IP addresses in the local configuration does nothing to ensure that existing connections are seamlessly transferred after a failover.

  • ✓

    Enable 'session-pickup' under config system ha

    Why this is correct

    Enabling session-pickup under the 'config system ha' block instructs the FortiGate to send session table information to the secondary unit on a continuous basis, allowing the standby to have a warm copy of all active connections, including those generated via virtual IPs. When a failover occurs, the backup unit has the necessary state to keep those VIP sessions active, so users do not experience a disruption. This is the central mechanism that makes stateful failover possible in FortiGate HA and is also required for sessions that originate through the VIP to be resumed on the new active device.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Fortinet exam blueprint

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.