Fixing Uneven Load on FortiGate Aggregate Interface
A FortiGate is configured with an aggregate interface (link aggregation group) consisting of two physical ports. The administrator notices that traffic is not being distributed evenly across the two links. Which configuration setting should be verified to improve load balancing?
Quick Answer
The answer is to verify the load-balancing algorithm for the aggregate interface. This is correct because the aggregate interface relies on a hashing algorithm—such as source-destination IP, MAC, or layer 4 port—to distribute traffic across member links; when the traffic pattern doesn’t align with the chosen algorithm, it can cause hash polarization and uneven distribution. On the Fortinet NSE 4 Network Security Professional exam, this question tests your understanding of link aggregation configuration and troubleshooting, often appearing as a scenario where an administrator sees one link saturated while the other is idle. A common trap is to assume the issue is physical (like cable faults) or to adjust the LACP mode, but the real fix lies in matching the algorithm to the traffic type. Memory tip: think “hash the flow, not the port”—the algorithm must hash on fields that vary across your traffic streams to spread load evenly.
⚠ Common exam trap
Many candidates confuse LACP negotiation settings (active/passive) with the actual traffic distribution mechanism, leading candidates to incorrectly select option A instead of recognizing that the load-balancing algorithm directly controls link utilization.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Verify the load-balancing algorithm for the aggregate interface
The aggregate interface uses a load-balancing algorithm to distribute traffic across member links. If traffic is uneven, the algorithm (e.g., source-destination IP, source-destination MAC, or layer 4 port) may not match the traffic pattern, causing hash polarization. Verifying and adjusting this algorithm is the correct step to improve distribution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Check the LACP mode (active vs passive)
Why it's wrong here
LACP mode affects negotiation but not traffic distribution.
- ✗
Increase the MTU on the aggregate interface
Why it's wrong here
MTU affects packet size but not load balancing.
- ✓
Verify the load-balancing algorithm for the aggregate interface
Why this is correct
The algorithm determines how traffic is hashed to links; changing it can improve distribution.
- ✗
Ensure the physical ports are in the same VDOM
Why it's wrong here
VDOM membership does not affect load balancing distribution.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
One of 282 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on NSE4
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. What is the purpose of configuring an aggregate interface on a FortiGate?
easy- A.To enable VLAN tagging on a physical interface
- ✓ B.To combine multiple physical interfaces into one logical interface for increased throughput and redundancy
- C.To separate management traffic from data traffic
- D.To connect two different network segments with a firewall in between
Why B: An aggregate interface (also known as a Link Aggregation Group or LAG) combines multiple physical FortiGate interfaces into a single logical interface. This increases throughput by load-balancing traffic across the member links and provides redundancy: if one physical link fails, traffic continues over the remaining links. FortiGate supports both static aggregation and LACP (IEEE 802.3ad) for dynamic negotiation.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.