NSE4 High Availability and Diagnostics Practice Question
A FortiGate HA cluster is operating in active-passive mode. The active unit fails over to the passive unit. After the failover, some existing TCP sessions are dropped. What is the MOST likely cause?
⚠ Common exam trap
NSE4 often tests the misconception that NAT prevents session synchronization or that failover speed alone determines session continuity, when in fact session synchronization must be explicitly enabled and operational for existing sessions to survive a failover.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Session synchronization is not enabled or not working properly
In an active-passive FortiGate HA cluster, the passive unit only maintains existing TCP sessions if session synchronization (session-pickup) is enabled and functioning. When the active unit fails, the passive unit becomes active and must have the session state to continue forwarding packets for established connections. If session synchronization is not enabled or is broken (e.g., due to a misconfigured sync interface or high latency), the new active unit has no knowledge of existing sessions and drops them, forcing clients to re-establish connections. Thus, the most likely cause is that session synchronization is not enabled or not working properly.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The HA heartbeat interface has a high latency
Why it's wrong here
High heartbeat latency can cause the HA cluster to misinterpret the peer's health and trigger unnecessary failovers, but it does not directly affect session state replication. The session table is synchronized over the same heartbeat interface, but latency alone does not erase the synchronized data; it may cause a delayed failover or split-brain. A properly synchronized session table would still be preserved after failover, so this is not the reason established TCP sessions are dropped.
- ✗
The failover time is too slow, causing TCP timeouts
Why it's wrong here
If the failover time is too slow, there is a gap during which no traffic is processed, and TCP sessions may time out due to missed retransmissions. However, this is an availability problem that affects even new sessions, not a persistence failure specific to existing connections. The core issue here is that existing sessions are dropped even after the new active unit comes up, which points to missing session synchronization, not the speed of the transition.
- ✓
Session synchronization is not enabled or not working properly
Why this is correct
In active-passive HA, the standby unit does not have the active unit's session table unless session pickup (session synchronization) is enabled and functioning. When a failover occurs, the newly active unit has no knowledge of the established TCP connections, so it cannot forward packets for those flows and they must be re-established. If session sync is enabled but not working, the same result occurs, so the correct fix is to verify that the session pickup feature is properly configured and that heartbeat interface is carrying the synchronization updates.
- ✗
The TCP sessions are using NAT, which cannot be synchronized
Why it's wrong here
NAT sessions are fully sessionizable; FortiGate's session sync includes the NAT translation state, such as source/destination IP and port mappings. There is no restriction in FortiOS that prevents NATed traffic from being synchronized across an HA pair. If NAT caused session drops after failover, even non-NAT sessions would survive, but in this scenario the administrator reports all TCP sessions being dropped, which indicates session sync is not active, not a NAT limitation.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Fortinet exam blueprint
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.