Courseiva

Why TCP Sessions Drop After FortiGate HA Failover and How to Fix

An administrator configures an HA cluster of two FortiGates in active-passive mode. The cluster is synchronized, but after a failover, some existing TCP sessions are dropped. What is the most likely cause?

⚠ Common exam trap

Watch out — candidates often confuse virtual MAC addressing or heartbeat configuration with session state replication, but the core requirement for session persistence after failover is session-pickup being enabled.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Session synchronization (session-pickup) is disabled

Session synchronization (session-pickup) is required for active-passive HA clusters to replicate TCP session state from the primary FortiGate to the secondary. When disabled, the backup unit has no knowledge of existing sessions after a failover, causing those sessions to be dropped because the new primary cannot match incoming packets to any session table entry.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The heartbeat interface is configured as a dedicated management interface

    Why it's wrong here

    Dedicating the heartbeat interface to management traffic is not the root cause of session drops during failover. The heartbeat link is responsible for cluster control messages and session synchronization payload between HA members; when it also carries management traffic, it can suffer congestion or increased latency, but that would impair the cluster's ability to sync state, not directly zero out the session table. Session loss on failover is specifically a consequence of disabled session pickup, not of sharing the heartbeat link.

  • ✓

    Session synchronization (session-pickup) is disabled

    Why this is correct

    Session synchronization, also called session pickup on FortiGate, is the feature that continuously replicates the primary unit's session table to the standby unit. When session-pickup is disabled, the standby device boots or takes over with an empty session table, so every existing TCP and UDP flow must be re-established, causing application interruptions and lost user sessions. This is the only option that directly explains why sessions are dropped during a failover event.

  • ✗

    The cluster is operating in NAT mode

    Why it's wrong here

    Whether the cluster runs in NAT mode or transparent mode does not determine session persistence across failover. FortiOS HA supports session-pickup in both operating modes, so a properly synchronized NAT-mode cluster will maintain sessions identically to a transparent-mode cluster. Therefore, selecting NAT mode as the cause confuses a deployment parameter with the actual state-synchronization mechanism.

  • ✗

    The cluster is using a virtual MAC address for the HA interface

    Why it's wrong here

    Using a virtual MAC address for the HA interface is a standard failover optimization that prevents ARP table staleness by updating the switch's forwarding table immediately when the active unit changes. While this improves network-level convergence, it does not affect the session state information that lives in the FortiGate's session table. Sessions are lost only if that table wasn't mirrored to the new primary, so virtual MAC is irrelevant to session-drop behavior.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.