Why TCP Sessions Drop After FortiGate HA Failover and How to Fix
An administrator configures an HA cluster of two FortiGates in active-passive mode. The cluster is synchronized, but after a failover, some existing TCP sessions are dropped. What is the most likely cause?
⚠ Common exam trap
Watch out — candidates often confuse virtual MAC addressing or heartbeat configuration with session state replication, but the core requirement for session persistence after failover is session-pickup being enabled.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Session synchronization (session-pickup) is disabled
Session synchronization (session-pickup) is required for active-passive HA clusters to replicate TCP session state from the primary FortiGate to the secondary. When disabled, the backup unit has no knowledge of existing sessions after a failover, causing those sessions to be dropped because the new primary cannot match incoming packets to any session table entry.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The heartbeat interface is configured as a dedicated management interface
Why it's wrong here
Dedicating the heartbeat interface to management traffic is not the root cause of session drops during failover. The heartbeat link is responsible for cluster control messages and session synchronization payload between HA members; when it also carries management traffic, it can suffer congestion or increased latency, but that would impair the cluster's ability to sync state, not directly zero out the session table. Session loss on failover is specifically a consequence of disabled session pickup, not of sharing the heartbeat link.
- ✓
Session synchronization (session-pickup) is disabled
Why this is correct
Session synchronization, also called session pickup on FortiGate, is the feature that continuously replicates the primary unit's session table to the standby unit. When session-pickup is disabled, the standby device boots or takes over with an empty session table, so every existing TCP and UDP flow must be re-established, causing application interruptions and lost user sessions. This is the only option that directly explains why sessions are dropped during a failover event.
- ✗
The cluster is operating in NAT mode
Why it's wrong here
Whether the cluster runs in NAT mode or transparent mode does not determine session persistence across failover. FortiOS HA supports session-pickup in both operating modes, so a properly synchronized NAT-mode cluster will maintain sessions identically to a transparent-mode cluster. Therefore, selecting NAT mode as the cause confuses a deployment parameter with the actual state-synchronization mechanism.
- ✗
The cluster is using a virtual MAC address for the HA interface
Why it's wrong here
Using a virtual MAC address for the HA interface is a standard failover optimization that prevents ARP table staleness by updating the switch's forwarding table immediately when the active unit changes. While this improves network-level convergence, it does not affect the session state information that lives in the FortiGate's session table. Sessions are lost only if that table wasn't mirrored to the new primary, so virtual MAC is irrelevant to session-drop behavior.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.