NSE7 Advanced Networking and SD-WAN Practice Question
A FortiGate has two equal-cost paths to a destination network through two different ISPs. The administrator wants to load balance traffic across both links using ECMP, but notices that all traffic uses only one link. What should the administrator check first?
⚠ Common exam trap
The trap here is that candidates often jump to configuring ECMP hashing modes or interface settings, overlooking the fundamental requirement that routes must be truly equal in administrative distance and priority before ECMP can function.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Check that both routes have the same administrative distance and priority
ECMP requires that all candidate routes have identical administrative distance and priority values. If either differs, FortiGate will select only the route with the lower distance/priority, breaking load balancing. The administrator should verify these parameters first because they directly control route selection before ECMP is applied.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Check that both routes have the same administrative distance and priority
Why this is correct
ECMP installs multiple next-hops only when candidate routes match on administrative distance and priority; differing values leave a single best route, so all traffic egresses one ISP. Verifying both attributes equal confirms the routes are genuinely equal-cost before troubleshooting hashing or link health.
- ✗
Configure 'set v4-ecmp-mode' to 'source-ip-based'
Why it's wrong here
Source-IP-based mode hashes each source to one path, so a single host's traffic still traverses only one link — the symptom persists. It is tempting because it does spread sessions across links, and would suit many-to-many traffic where per-flow distribution is acceptable.
- ✗
Verify that 'set load-balance-eligible' is enabled on both WAN interfaces
Why it's wrong here
FortiOS has no 'load-balance-eligible' interface setting; ECMP path selection is governed by the routing table and v4-ecmp-mode, so this check yields nothing. It tempts administrators who recall SD-WAN's load-balance enable toggle, which applies to SD-WAN zones rather than plain ECMP routes.
- ✗
Disable 'anti-replay' on the security policy
Why it's wrong here
Anti-replay is an IPsec feature that drops duplicate sequence numbers; it has no bearing on ECMP route selection or hashing. It is tempting because asymmetric paths can trigger replay drops, so it would be the correct check when IPsec traffic fails over ECMP links.
Go deeper
Related to this question
About these practice questions
Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.