Courseiva

NSE4 ECMP Practice Question

After upgrading FortiGate firmware, the administrator notices that the 'config router static' command now shows a new keyword 'distance' instead of 'weight'. The upgrade also changed the ECMP load-balancing behavior. What was the likely change in the ECMP algorithm?

⚠ Common exam trap

The trap is that candidates may assume the change was from source-IP-based to weighted because the new keyword 'distance' seems like a weight metric. However, the actual change was from weighted to source-IP-based hash, as the 'weight' parameter was deprecated and replaced by 'distance' for administrative distance, not for load-balancing weight.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The ECMP algorithm changed from weighted to source-dest-IP

In FortiOS 6.4, the default ECMP method was weighted, using the 'weight' parameter in static routes. Starting with FortiOS 7.0, the 'weight' parameter was replaced by 'distance', and the default ECMP algorithm changed to source-IP-based hash (also referred to as source-dest-IP hash). This change enhances load balancing by distributing traffic based on source/destination IP addresses rather than priority weights.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The ECMP algorithm changed from source-IP-based to weighted (hash-based)

    Why it's wrong here

    The transition moved away from weighted load balancing, not toward it. The upgrade changed from a weighted distribution, where each route's 'weight' controlled the proportion of traffic share, to a hash-based distribution that uses address tuples. The replacement of 'weight' with 'distance' in route configuration confirms that weighted load balancing was eliminated, so the direction of the change is reversed from what this option states.

  • ✓

    The ECMP algorithm changed from weighted to source-dest-IP

    Why this is correct

    The FortiOS upgrade replaced the legacy weighted ECMP algorithm with a hash-based algorithm that hashes both the source and destination IP addresses (source-dest-IP-based). Previously, the route's 'weight' value determined how much traffic each path carried; after the upgrade, that weight attribute is no longer used, and path selection for a session is deterministic based on the source and destination IP pair, ensuring session stickiness. The 'distance' setting still influences route selection but does not provide proportional load sharing; this is the default behavior in the upgraded FortiOS environment.

  • ✗

    The ECMP algorithm is now configurable via 'config system ecmp'

    Why it's wrong here

    There is no 'config system ecmp' command in FortiOS. ECMP load-balancing behavior is configured under 'config system settings' using the 'v4-ecmp-mode' and 'v6-ecmp-mode' settings, where you can select a hash algorithm or weighted mode. The administrator would not find a dedicated ECMP configuration submenu; the upgrade does not introduce such a command.

  • ✗

    The ECMP algorithm changed from source-dest-IP to round-robin

    Why it's wrong here

    The change did not involve round-robin. The pre-upgrade algorithm was weighted, not source-dest-IP-based, and the post-upgrade algorithm is a hash-based method (source-IP or source-dest-IP), not round-robin. Round-robin would send successive new sessions to successive paths in sequential order, whereas a hash algorithm consistently maps session characteristics to a single path, which is not the behavior described.

About these practice questions

Courseiva writes every NSE4 question from scratch — 773 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.