Courseiva

NSE7 Advanced Networking and SD-WAN Practice Question

A FortiGate has two equal-cost paths to a destination network through two different ISPs. The administrator wants to load balance traffic across both links using ECMP, but notices that all traffic uses only one link. What should the administrator check first?

⚠ Common exam trap

The trap here is that candidates often jump to configuring ECMP hashing modes or interface settings, overlooking the fundamental requirement that routes must be truly equal in administrative distance and priority before ECMP can function.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Check that both routes have the same administrative distance and priority

ECMP requires that all candidate routes have identical administrative distance and priority values. If either differs, FortiGate will select only the route with the lower distance/priority, breaking load balancing. The administrator should verify these parameters first because they directly control route selection before ECMP is applied.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Check that both routes have the same administrative distance and priority

    Why this is correct

    ECMP installs multiple next-hops only when candidate routes match on administrative distance and priority; differing values leave a single best route, so all traffic egresses one ISP. Verifying both attributes equal confirms the routes are genuinely equal-cost before troubleshooting hashing or link health.

  • ✗

    Configure 'set v4-ecmp-mode' to 'source-ip-based'

    Why it's wrong here

    Source-IP-based mode hashes each source to one path, so a single host's traffic still traverses only one link — the symptom persists. It is tempting because it does spread sessions across links, and would suit many-to-many traffic where per-flow distribution is acceptable.

  • ✗

    Verify that 'set load-balance-eligible' is enabled on both WAN interfaces

    Why it's wrong here

    FortiOS has no 'load-balance-eligible' interface setting; ECMP path selection is governed by the routing table and v4-ecmp-mode, so this check yields nothing. It tempts administrators who recall SD-WAN's load-balance enable toggle, which applies to SD-WAN zones rather than plain ECMP routes.

  • ✗

    Disable 'anti-replay' on the security policy

    Why it's wrong here

    Anti-replay is an IPsec feature that drops duplicate sequence numbers; it has no bearing on ECMP route selection or hashing. It is tempting because asymmetric paths can trigger replay drops, so it would be the correct check when IPsec traffic fails over ECMP links.

About these practice questions

Courseiva writes every NSE7 question from scratch — 718 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.