NSE4 High Availability and Diagnostics Practice Question
Which TWO statements about FortiGate HA heartbeat interfaces are correct?
⚠ Common exam trap
It's easy for candidates to assume heartbeat interfaces must be in the same VDOM (Option A) because they think VDOM boundaries restrict HA communication, but FortiGate HA operates at the system level and can use interfaces from different VDOMs as long as they share a subnet.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Heartbeat interfaces must be on the same subnet.
FortiGate HA heartbeat interfaces must be on the same subnet to allow the heartbeat packets (typically UDP port 496) to be exchanged directly between the primary and secondary units. This ensures Layer 2 adjacency is maintained for reliable failure detection and synchronization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Heartbeat interfaces must be in the same VDOM.
Why it's wrong here
HA heartbeat interfaces are configured globally in the HA settings and are not tied to any specific VDOM. Even on FortiGates running multiple VDOMs, the same physical interface can carry heartbeat traffic while simultaneously being assigned to different VDOMs or even no VDOM at all. The heartbeat protocol operates below the VDOM layer, so VDOM membership has no effect on heartbeat communication.
- ✗
Heartbeat interfaces must be dedicated management ports.
Why it's wrong here
FortiGate HA heartbeat links are not required to use dedicated management ports; any physical data port can be designated as a heartbeat interface. Management ports such as the MGMT port are typically reserved for out-of-band administrative access and may not even be capable of carrying HA traffic on all models. For optimal reliability you should use a dedicated internal switch or a crossover cable on a regular interface, not the management port.
- ✓
Heartbeat interfaces must be on the same subnet.
Why this is correct
For HA heartbeat to work, the heartbeat interfaces on both FortiGates must be in the same subnet, typically via a direct crossover connection or through a switch on the same VLAN. This is because heartbeat packets are sent as Ethernet frames (often multicast) and require Layer 2 adjacency; without a shared broadcast domain, the units cannot detect each other or exchange session-synchronization data. If the heartbeat interfaces are on different subnets, the HA cluster will never form.
- ✓
Heartbeat traffic is not encrypted by default.
Why this is correct
By default, FortiGate HA heartbeat traffic, including session synchronization and device configuration sync, is transmitted in clear text. This means any attacker able to sniff the heartbeat link can intercept sensitive session information, so Fortinet recommends enabling encryption in the HA settings via the 'set encryption enable' command and configuring a shared secret. Encrypting heartbeat traffic increases CPU overhead but is essential for security, especially when heartbeat links pass over untrusted infrastructure.
- ✗
Only two heartbeat interfaces can be configured.
Why it's wrong here
FortiGate supports multiple heartbeat interfaces, not just two; the exact maximum depends on the platform, but it is typically up to eight. You can configure several heartbeat links concurrently to provide redundancy and to increase session-synchronization bandwidth by setting them in override mode or as backup links. Limiting HA to two heartbeat interfaces is not a platform constraint, so this statement is false.
Visual reference
Go deeper
Related to this question
About these practice questions
This NSE4 question is part of Courseiva's 773-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE4 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE4 exam.