Courseiva

NSE4 System and Network Administration Practice Question

A FortiGate has two WAN interfaces (wan1, wan2) configured with ECMP routes to the same destination. The administrator notices that traffic for a single session is being load-balanced across both links, causing performance issues. What should be configured to ensure sessions stick to one link?

⚠ Common exam trap

A common mix-up: candidates confuse ECMP load balancing methods with SD-WAN stickiness features, assuming SD-WAN is required for session persistence, when in fact ECMP’s hash algorithm can be tuned directly to achieve per-session stickiness.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Change ECMP load balancing method to 'source-ip-based' or 'source-dst-ip-based'.

Changing the ECMP load balancing method to 'source-ip-based' or 'source-dst-ip-based' ensures that all packets belonging to the same session (identified by source IP or source-destination IP pair) are hashed to the same egress interface. This prevents a single session from being split across multiple WAN links, which can cause out-of-order packets and performance degradation. FortiGate’s ECMP hash algorithm uses the configured method to compute a hash value that deterministically selects the outgoing interface for each flow.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set policy routing to use source-based routing.

    Why it's wrong here

    Policy routing alters the forwarding decision before the route lookup, and while it can direct specific source subnets toward a particular WAN, it is a manual, rule-based override rather than a dynamic, hashing-based load balancing method. It does not change the ECMP hashing used for the default routes, so unrelated traffic may still suffer from session instability. The correct fix is to adjust the ECMP load balancing algorithm itself, not to add policy routes.

  • ✓

    Change ECMP load balancing method to 'source-ip-based' or 'source-dst-ip-based'.

    Why this is correct

    Changing the ECMP load balancing method to 'source-ip-based' or 'source-dst-ip-based' forces the FortiGate to compute a deterministic hash from either the source IP alone or the source-destination IP pair for each session. All packets in a session share the same hash value, so they are consistently forwarded out the same WAN interface, preventing out-of-order delivery and dropped sessions. This is the built-in, scalable mechanism for per-session stickiness across equal-cost routes.

  • ✗

    Configure SD-WAN rules to enforce per-session stickiness.

    Why it's wrong here

    SD-WAN rules steer traffic based on performance metrics and policy, but they operate above the routing table and do not directly control the ECMP hash used for default routes. Even if SD-WAN is enabled, the underlying ECMP algorithm still needs to be configured for stickiness unless a specific rule explicitly pins a session to one interface, which is not a global fix. Relying on SD-WAN for this task is an indirect, complex workaround when the ECMP setting is the straightforward solution.

  • ✗

    Disable ECMP and use a single default route.

    Why it's wrong here

    Disabling ECMP by removing the second default route would force all traffic out a single WAN interface, eliminating session instability but also eliminating redundancy and load sharing. This reduces throughput by half and creates a single point of failure. A better approach is to keep both routes and simply change the ECMP hashing so that sessions stick to one interface without sacrificing bandwidth.

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.