Courseiva

NSE4 System and Network Administration Practice Question

Which TWO of the following are prerequisites for configuring a high availability (HA) cluster on FortiGate? (Choose two.)

⚠ Common exam trap

Test-takers frequently assume identical configuration is required before forming the cluster, but FortiGate automatically synchronizes the primary's configuration to the secondary, making pre-existing identical configs unnecessary.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The FortiGate units must be running the same firmware version.

FortiGate HA requires all cluster members to run the same firmware version to ensure configuration compatibility and consistent behavior. Mismatched firmware can lead to synchronization failures or unpredictable failover events, as the HA heartbeat and session synchronization protocols depend on identical code bases.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    An HA heartbeat interface must be a dedicated interface.

    Why it's wrong here

    For FortiGate HA, the heartbeat link does not have to be a dedicated physical interface. While using a dedicated interface is a best practice to isolate heartbeat traffic from data traffic and improve stability, FortiGate supports sharing heartbeat on an interface that also carries user traffic, such as a VLAN or a physical port. The key requirement is that the heartbeat interface must be reachable between the two units and configured appropriately, not that it is exclusively reserved for HA communication.

  • ✗

    All interfaces must be configured with static IP addresses.

    Why it's wrong here

    FortiGate HA does not mandate static IP addresses on all interfaces. In fact, many deployments use DHCP for WAN or other uplinks, and HA configuration synchronizes the learned or configured addresses; however, certain HA management or dedicated heartbeat interfaces may need static or well-known addresses to ensure connectivity. The actual prerequisites focus on firmware, hardware model, and specific HA settings like interface monitoring, not on every interface having a static IP.

  • ✓

    The FortiGate units must be running the same firmware version.

    Why this is correct

    Running the same firmware version is a strict prerequisite for FortiGate HA. Both units must have the exact same FortiOS build, including any minor patches or hotfixes, because differences in firmware can cause protocol incompatibilities and prevent successful HA synchronization. Even minor version discrepancies can break the HA heartbeat and failover behavior, so Fortinet requires matching firmware before enabling HA.

  • ✗

    The configuration must be identical on both units.

    Why it's wrong here

    The configuration does not need to be identical on both units before HA is established, because the primary unit's configuration is automatically synchronized to the secondary unit during HA formation. The whole purpose of HA is to replicate configuration from the active unit to the standby unit, so pre-matching configurations is unnecessary. What matters is that both units have a minimal configuration to support HA (e.g., administrative access, heartbeat), and the primary's full configuration is then pushed to the peer.

  • ✓

    The FortiGate units must be the same model.

    Why this is correct

    The FortiGate units must be the same model for HA to work. Different models have different hardware capabilities, such as CPU, memory, and interface counts, and Fortinet's HA implementation requires matching hardware to ensure consistent performance and configuration compatibility. A FortiGate 100F cannot form an HA cluster with a 200F, even if running the same firmware, because the resource capacities and interface mappings differ.

About these practice questions

One of 773 original NSE4 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on NSE4

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which protocol does FortiGate use to synchronize sessions between HA cluster members?

easy
  • A.HSRP
  • B.OSPF
  • C.VRRP
  • ✓ D.FGCP

Why D: FortiGate uses the FortiGate Cluster Protocol (FGCP) to synchronize session tables, configuration, and state information between HA cluster members. FGCP is a proprietary protocol that ensures seamless failover by replicating session data in real time, allowing the backup unit to take over active sessions without interruption.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.