NSE4 High Availability and Diagnostics Practice Question
A FortiGate administrator has configured an active-passive HA cluster with two units. During a failover test, they notice that existing TCP sessions are dropped and must be re-established. What configuration change should the administrator make to ensure sessions are preserved during failover?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable session synchronization between the cluster members
Session synchronization (session sync) allows the active unit to share session table entries with the passive unit. During failover, the new active unit has the session table pre-populated, so existing sessions continue without interruption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable session synchronization between the cluster members
Why this is correct
Enabling session synchronization (session sync) in the HA cluster causes the active FortiGate to continuously replicate its entire session table — including NAT mappings, TCP sequence numbers, and timers — to the standby unit over the heartbeat link. Because the standby now possesses an up-to-date copy of all state, it can immediately assume forwarding during a failover and existing TCP sessions remain intact without client reconnection. Without this feature, no amount of heartbeat, priority, or override tuning can save sessions; this is the only mechanism that directly addresses session preservation.
- ✗
Configure a dedicated heartbeat interface
Why it's wrong here
A dedicated heartbeat interface is the recommended way to separate cluster control traffic and session synchronization from data traffic, improving reliability and preventing congestion. However, this interface is just the transport path for the synchronization data; its mere existence does not create session state. If session synchronization is disabled, the standby unit will still have no session table to use after failover, so adding a heartbeat interface alone does nothing to preserve TCP sessions.
- ✗
Enable HA override
Why it's wrong here
HA override, when enabled, instructs the preferred primary unit to take back the primary role immediately after it recovers from an outage, even if the current active unit is operating normally. This setting is purely about role reassertion and administrative preference, ensuring traffic returns to the initially preferred device. It has no effect on session state replication, so existing sessions are neither saved nor restored by enabling override.
- ✗
Increase the HA priority on the primary unit
Why it's wrong here
Increasing the HA priority on the primary unit raises its preference during the cluster's election process, making it more likely to become active at startup or after a failover. This value is simply a numerical ranking used to break ties and decide which unit is primary. Priority changes do not instruct the unit to copy session state to its peer, so they are completely unrelated to keeping established TCP connections alive during a failover.
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.