Courseiva

NSE7 Enterprise Firewall and VDOMs Practice Question

A FortiGate in an HA cluster with VDOMs enabled experiences a failover. After the failover, traffic that was passing before is now being dropped. The configuration is synchronized between the primary and secondary units. What is the most likely reason?

⚠ Common exam trap

Many candidates assume synchronized configuration includes session state, but FortiGate HA separates configuration sync from session sync, and session synchronization must be enabled as a separate setting under the HA configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Session synchronization is not enabled between HA members

The most likely reason is that session synchronization is not enabled between HA members. When a failover occurs, the new primary FortiGate does not have the existing session table entries from the original primary, so it treats incoming packets as new connections and may drop them if they do not match a firewall policy's initial handshake state. Even though the configuration is synchronized, session information is not shared unless session synchronization is explicitly configured, causing traffic to be dropped after failover.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The new primary has a different VDOM configuration

    Why it's wrong here

    HA configuration synchronisation copies the entire VDOM configuration to the secondary, so the new primary cannot have a different VDOM configuration after failover. It is tempting because mismatched configuration is a frequent HA fault, but with VDOMs enabled the synchronisation covers all VDOMs, making this impossible in the stated scenario.

  • ✗

    The firewall policies are not synchronized

    Why it's wrong here

    Firewall policies are part of the HA configuration and synchronise automatically, so a mismatch is unlikely when the units report in sync. This would be the cause if configuration sync had failed or a policy were added on one unit only. The actual issue is that VDOM-level settings such as NPU or session pickup are not synchronised.

  • ✓

    Session synchronization is not enabled between HA members

    Why this is correct

    Without session synchronization, the secondary FortiGate lacks the connection table for established flows, so after failover it drops packets belonging to existing sessions. Configuration synchronisation alone does not replicate session state, explaining why previously passing traffic now fails.

  • ✗

    VDOM link interfaces are down on the new primary

    Why it's wrong here

    VDOM link interfaces are virtual internal connections between VDOMs, not physical HA-monitored interfaces; they do not fail over or go down on a new primary, so this cannot explain dropped traffic. It is tempting because interface state is a common HA cause, but VDOM links stay up as long as both VDOMs exist.

Visual reference

Client Server SYN (seq=100) SYN-ACK (seq=200, ack=101) ACK (ack=201) Connection established — data transfer begins

About these practice questions

This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.