NSE4 High Availability and Diagnostics Practice Question
An administrator configures a FortiGate HA cluster in active-active mode. After enabling session synchronization, they notice that new sessions are not being synced to the secondary unit. The cluster is using a dedicated heartbeat interface. What could be the reason?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The firewall policy does not have session sync enabled
In active-active HA, session synchronization requires that the session sync flag is enabled on the firewall policy. Without it, sessions are not synced.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The HA mode is set to active-passive
Why it's wrong here
In an active-passive HA cluster, only the primary unit processes traffic and the standby unit remains idle, so session synchronization is a unidirectional replication for failover rather than a per-policy requirement. The scenario specifically states the cluster is configured in active-active mode, so this answer contradicts the given premise. Even if the mode were changed, the visible symptom of sessions not being synchronized between participating units would not match an active-passive configuration.
- ✓
The firewall policy does not have session sync enabled
Why this is correct
In FortiGate active-active HA, session synchronization is not automatic — it must be enabled individually on each firewall policy using the 'session sync' option in the policy's advanced settings. Without this setting, each session is tracked only by the specific cluster unit that received its first packet, and if that unit fails or return traffic is load-balanced to a peer, the session is unknown to the other unit. This directly prevents the session table from being shared, which is exactly why the administrator observes no session synchronization.
- ✗
The session TTL is too short
Why it's wrong here
Session TTL determines how long a session remains in the session table after the last matching packet, so a short TTL only causes idle sessions to age out prematurely on every cluster unit. It does not interfere with the HA session synchronization process itself, because the replication mechanism will still copy session entries to the peer before they expire. Therefore, a short TTL might cause connections to drop unexpectedly, but it cannot explain the complete absence of session synchronization between cluster members.
- ✗
The heartbeat interface is not configured with an IP address
Why it's wrong here
FortiGate heartbeat interfaces are used for heartbeat messages and, in some configurations, to carry session synchronization traffic, but they do not require manually assigned IP addresses because the units automatically use link-local addressing. An unnumbered heartbeat interface is normal and functions correctly, so the absence of an IP address on it would not prevent HA formation or session synchronization. The cluster would simply use link-local communication to negotiate roles and replicate session tables.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.