NSE4 System and Network Administration Practice Question
A FortiGate is configured with two WAN interfaces (port1 and port2) connected to different ISPs. The administrator wants to load-balance outbound traffic across both links using equal-cost routes. Which routing configuration should be applied?
⚠ Common exam trap
Watch out — candidates often confuse 'different distances' (which creates failover) with 'equal distances' (which enables load balancing), often selecting option D because they think varying metrics distributes traffic, but in reality, only equal administrative distances trigger ECMP load sharing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure static routes with equal distance and enable ECMP.
ECMP (Equal-Cost Multi-Path) routing allows a FortiGate to load-balance outbound traffic across multiple interfaces when static routes have the same distance (administrative distance) and destination. By configuring two static routes with equal distance (e.g., 10) to 0.0.0.0/0 via port1 and port2, the FortiGate automatically distributes sessions across both links using a hash-based algorithm (e.g., source-destination IP), achieving the desired load balancing without dynamic routing protocols.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure policy routes to direct traffic based on source IP.
Why it's wrong here
Configuring policy routes based on source IP forces specific source addresses to exit a chosen WAN interface, but it is a selective, rule-based override of the routing table rather than a general load-balancing mechanism. It cannot automatically distribute all outbound traffic across both WAN links without manually enumerating every source subnet, and it does not provide equal-cost multipath behavior. This approach is useful for traffic steering or application segregation, not for using two identical ISP links as an aggregated default path.
- ✗
Enable BGP to dynamically learn routes from both ISPs.
Why it's wrong here
Running BGP with both ISPs is an enterprise-grade solution that requires a public ASN, provider-owned IP space, and active peering agreements with each ISP; it is not a practical dual-WAN setup for a typical FortiGate edge. Even if BGP were used, without enabling multipath or equal-cost route installation, BGP would still select only a single best route for each prefix, so it would not inherently balance traffic. The question asks about static dual-WAN load sharing, where simple ECMP static routes are the standard, far simpler answer.
- ✓
Configure static routes with equal distance and enable ECMP.
Why this is correct
Static routes with equal administrative distance and priority to the same destination are installed as ECMP (Equal-Cost Multi-Path) routes, allowing the FortiGate to spread outbound traffic across both WAN interfaces simultaneously. The FortiGate supports several load-balancing algorithms for ECMP, such as source-IP-based, weight-based, or usage-based, enabling granular control while still using both links. This is the correct way to achieve dual-WAN load balancing with static routing, and it pairs well with link health monitors to remove dead links dynamically.
- ✗
Configure static routes with different distances (e.g., 10 and 20) to the same destination.
Why it's wrong here
Configuring static routes with different administrative distances (e.g., 10 and 20) creates an active/passive failover design, not load balancing. The route with distance 10 is always preferred, so all traffic uses that WAN link under normal conditions, while the distance-20 route only appears in the routing table when the primary link fails. This setup provides redundancy and avoids using both ISPs concurrently, which does not satisfy the requirement to utilize both WAN interfaces for load sharing.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.