What is the purpose of BFD (Bidirectional Forwarding Detection) in a FortiGate routing configuration?
BFD sends sub-second control packets over the forwarding path, so FortiGate can tear down a failed route or adjacency far faster than routing protocol hellos allow. This satisfies the stem's requirement for rapid failure detection, enabling quicker reconvergence than standard dead-interval timers.
Why this answer
BFD (Bidirectional Forwarding Detection) provides fast failure detection for forwarding paths between two adjacent routers, independent of any routing protocol. In FortiGate configurations, BFD is used to detect link or neighbor failures in sub-second intervals (e.g., 50-100 ms), enabling rapid convergence for dynamic routing protocols like OSPF or BGP. This is critical for SD-WAN and high-availability scenarios where traditional keepalive timers (e.g., OSPF Hello/Dead intervals of 10-40 seconds) are too slow.
Exam trap
The trap here is that candidates confuse BFD's role in fast failure detection with routing protocol features like authentication or encryption, or mistakenly think BFD itself provides load balancing, when in fact it only monitors path liveliness and triggers convergence.
How to eliminate wrong answers
Option A is wrong because BFD does not encrypt routing protocol traffic; encryption is handled by protocols like IPsec or authentication mechanisms within routing protocols (e.g., OSPF MD5 authentication). Option C is wrong because BFD does not authenticate routing peers; authentication is a separate feature of routing protocols (e.g., BGP MD5 password or OSPF authentication) and BFD itself has no authentication mechanism. Option D is wrong because BFD is a detection mechanism, not a load-balancing tool; load balancing across multiple paths is achieved by ECMP (Equal-Cost Multi-Path) routing or SD-WAN rules, while BFD simply detects failures on those paths.