NSE4 System and Network Administration Practice Question
Which TWO of the following are prerequisites for configuring a high availability (HA) cluster on FortiGate? (Choose two.)
⚠ Common exam trap
Test-takers frequently assume identical configuration is required before forming the cluster, but FortiGate automatically synchronizes the primary's configuration to the secondary, making pre-existing identical configs unnecessary.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The FortiGate units must be running the same firmware version.
FortiGate HA requires all cluster members to run the same firmware version to ensure configuration compatibility and consistent behavior. Mismatched firmware can lead to synchronization failures or unpredictable failover events, as the HA heartbeat and session synchronization protocols depend on identical code bases.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
An HA heartbeat interface must be a dedicated interface.
Why it's wrong here
For FortiGate HA, the heartbeat link does not have to be a dedicated physical interface. While using a dedicated interface is a best practice to isolate heartbeat traffic from data traffic and improve stability, FortiGate supports sharing heartbeat on an interface that also carries user traffic, such as a VLAN or a physical port. The key requirement is that the heartbeat interface must be reachable between the two units and configured appropriately, not that it is exclusively reserved for HA communication.
- ✗
All interfaces must be configured with static IP addresses.
Why it's wrong here
FortiGate HA does not mandate static IP addresses on all interfaces. In fact, many deployments use DHCP for WAN or other uplinks, and HA configuration synchronizes the learned or configured addresses; however, certain HA management or dedicated heartbeat interfaces may need static or well-known addresses to ensure connectivity. The actual prerequisites focus on firmware, hardware model, and specific HA settings like interface monitoring, not on every interface having a static IP.
- ✓
The FortiGate units must be running the same firmware version.
Why this is correct
Running the same firmware version is a strict prerequisite for FortiGate HA. Both units must have the exact same FortiOS build, including any minor patches or hotfixes, because differences in firmware can cause protocol incompatibilities and prevent successful HA synchronization. Even minor version discrepancies can break the HA heartbeat and failover behavior, so Fortinet requires matching firmware before enabling HA.
- ✗
The configuration must be identical on both units.
Why it's wrong here
The configuration does not need to be identical on both units before HA is established, because the primary unit's configuration is automatically synchronized to the secondary unit during HA formation. The whole purpose of HA is to replicate configuration from the active unit to the standby unit, so pre-matching configurations is unnecessary. What matters is that both units have a minimal configuration to support HA (e.g., administrative access, heartbeat), and the primary's full configuration is then pushed to the peer.
- ✓
The FortiGate units must be the same model.
Why this is correct
The FortiGate units must be the same model for HA to work. Different models have different hardware capabilities, such as CPU, memory, and interface counts, and Fortinet's HA implementation requires matching hardware to ensure consistent performance and configuration compatibility. A FortiGate 100F cannot form an HA cluster with a 200F, even if running the same firmware, because the resource capacities and interface mappings differ.
Go deeper
Related to this question
About these practice questions
One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on NSE4
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which protocol does FortiGate use to synchronize sessions between HA cluster members?
easy- A.HSRP
- B.OSPF
- C.VRRP
- ✓ D.FGCP
Why D: FortiGate uses the FortiGate Cluster Protocol (FGCP) to synchronize session tables, configuration, and state information between HA cluster members. FGCP is a proprietary protocol that ensures seamless failover by replicating session data in real time, allowing the backup unit to take over active sessions without interruption.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.