NSE7 Enterprise Firewall and VDOMs Practice Question
A FortiGate in an HA cluster with VDOMs enabled experiences a failover. After the failover, traffic that was passing before is now being dropped. The configuration is synchronized between the primary and secondary units. What is the most likely reason?
⚠ Common exam trap
Many candidates assume synchronized configuration includes session state, but FortiGate HA separates configuration sync from session sync, and session synchronization must be enabled as a separate setting under the HA configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Session synchronization is not enabled between HA members
The most likely reason is that session synchronization is not enabled between HA members. When a failover occurs, the new primary FortiGate does not have the existing session table entries from the original primary, so it treats incoming packets as new connections and may drop them if they do not match a firewall policy's initial handshake state. Even though the configuration is synchronized, session information is not shared unless session synchronization is explicitly configured, causing traffic to be dropped after failover.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The new primary has a different VDOM configuration
Why it's wrong here
HA configuration synchronisation copies the entire VDOM configuration to the secondary, so the new primary cannot have a different VDOM configuration after failover. It is tempting because mismatched configuration is a frequent HA fault, but with VDOMs enabled the synchronisation covers all VDOMs, making this impossible in the stated scenario.
- ✗
The firewall policies are not synchronized
Why it's wrong here
Firewall policies are part of the HA configuration and synchronise automatically, so a mismatch is unlikely when the units report in sync. This would be the cause if configuration sync had failed or a policy were added on one unit only. The actual issue is that VDOM-level settings such as NPU or session pickup are not synchronised.
- ✓
Session synchronization is not enabled between HA members
Why this is correct
Without session synchronization, the secondary FortiGate lacks the connection table for established flows, so after failover it drops packets belonging to existing sessions. Configuration synchronisation alone does not replicate session state, explaining why previously passing traffic now fails.
- ✗
VDOM link interfaces are down on the new primary
Why it's wrong here
VDOM link interfaces are virtual internal connections between VDOMs, not physical HA-monitored interfaces; they do not fail over or go down on a new primary, so this cannot explain dropped traffic. It is tempting because interface state is a common HA cause, but VDOM links stay up as long as both VDOMs exist.
Visual reference
Go deeper
Related to this question
About these practice questions
This NSE7 question is part of Courseiva's 718-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This NSE7 practice question is part of Courseiva's free Fortinet certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the NSE7 exam.