Courseiva

ECMP Load Balancing on FortiGate

A network administrator configures a new FortiGate as the default gateway for a subnet. The FortiGate has two WAN interfaces (port1 and port2) connected to different ISPs. The admin wants to load-balance outbound traffic across both links. Which configuration method will achieve this goal?

Quick Answer

The answer is to configure two static default routes with the same distance and metric. This configuration enables Equal-Cost Multi-Path (ECMP) routing on the FortiGate, which allows the device to load-balance outbound traffic across both WAN interfaces by treating the two paths as equally preferred. ECMP load balancing on FortiGate distributes sessions between the ISPs using either a per-flow or per-packet algorithm, ensuring that no single link is overwhelmed. On the Fortinet NSE 4 Network Security Professional exam, this scenario tests your understanding of how route selection and load balancing interact—specifically that ECMP is triggered only when distance and metric are identical, not when they differ. A common trap is to assume policy routing or SD-WAN rules are required, but for basic outbound load balancing, ECMP is the simplest native method. Memory tip: “Same distance, same metric—ECMP is automatic.”

⚠ Common exam trap

A common mix-up: candidates confuse ECMP (same distance/metric) with floating static routes (different distances), mistakenly thinking that multiple default routes with different distances will load-balance, when in fact they only provide failover.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure two static default routes with the same distance and metric

Configuring two static default routes with the same distance and metric enables ECMP (Equal-Cost Multi-Path) routing on FortiGate. This allows the FortiGate to load-balance outbound traffic across both WAN interfaces (port1 and port2) using a per-flow or per-packet algorithm, distributing sessions between the two ISPs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a single default gateway and rely on ARP for failover

    Why it's wrong here

    A single default gateway with ARP failover provides only redundancy, not load balancing across both ISPs. It is tempting because ARP failover is simple and link-state based, but ECMP or SD-WAN rules are required to distribute sessions across two WAN links.

  • ✗

    Configure a policy route for each subnet directing traffic to a different ISP

    Why it's wrong here

    A policy route steers matching traffic down one named outgoing interface, so each subnet still uses a single ISP rather than sharing load across both. It is tempting because policy routes are genuinely for directing specific traffic by source, destination or service — correct when you must force certain subnets down a particular link, not for per-flow balancing.

  • ✗

    Configure two static default routes with different distances

    Why it's wrong here

    Two static default routes with different distances create an active/standby failover, since only the lowest-distance route enters the routing table. Equal-distance routes are tempting because ECMP does load-balance, but FortiGate static routes require equal distance and priority to achieve that.

  • ✓

    Configure two static default routes with the same distance and metric

    Why this is correct

    Two static default routes with equal distance and metric create ECMP, so the FortiGate distributes outbound sessions across port1 and port2. This satisfies the load-balancing requirement without policy routes. Unequal distance would make one route standby only, defeating the goal.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on NSE4

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An administrator is configuring ECMP (Equal-Cost Multi-Path) on a FortiGate. Which TWO conditions are required for ECMP to load balance traffic across multiple routes?

medium
  • A.Routes must use different next-hop IP addresses
  • ✓ B.Routes must have the same priority setting
  • ✓ C.Routes must have the same administrative distance
  • D.Routes must be static routes only
  • E.Routes must be through different interfaces

Why B: ECMP requires that multiple routes have the same priority (also known as 'distance' in some contexts) to be considered equal-cost. In FortiGate, priority is a metric that determines route preference; only routes with identical priority can be used simultaneously for load balancing. Option C is also correct because administrative distance must be the same for routes to be considered equal; if administrative distances differ, the route with the lower distance is preferred, and ECMP will not apply.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.