A network architect is designing a resilient campus network using a FortiGate HA Active-Passive cluster connected to a pair of core FortiSwitches in a stack. The design requires that downstream access switches maintain connectivity during a FortiGate failover event. Which configuration is essential on the core FortiSwitch stack to ensure seamless failover and connectivity?
Answer and explanation
Correct answer: B
For a resilient connection to a FortiGate HA cluster, the best practice is to configure the FortiLink interface as an 802.3ad aggregate interface on the FortiGate side. On the FortiSwitch stack, a corresponding LACP trunk (LAG) is created with member ports physically connecting to each core switch. This configuration, known as MCLAG FortiLink, ensures that the logical link remains up even if one of the core switches or one of the physical links to the FortiGate fails, aligning perfectly with the HA capabilities of the FortiGate cluster.
Question 2
Multiple answers
A security administrator is hardening untrusted access-layer FortiSwitch ports against common Layer 2 spoofing attacks. To create a multi-layered defense, they plan to implement DHCP Snooping, Dynamic ARP Inspection (DAI), and IP Source Guard. Which THREE statements accurately describe the implementation and dependencies of these features? (Select THREE)
Answer and explanation
Correct answers: A, C, E
Question 3
An administrator manages a large-scale deployment of over 100 FortiSwitches using a global FortiSwitch Template on a FortiGate. A new requirement mandates that all switches in the engineering department's wiring closets must have PoE disabled on ports 1-12. What is the most efficient and scalable method to apply this specific configuration without affecting the other 80+ switches?
Answer and explanation
Correct answer: B
The FortiSwitch Template model is designed for this type of scenario. While manual CLI changes or per-switch overrides work for single instances, they are not scalable or maintainable. The most efficient and correct method is to create a new template (often by cloning the base template) that contains the specific settings for the engineering group (PoE disabled). This new template is then assigned to all switches designated for the engineering department. This approach maintains centralized management, ensures consistency, and simplifies future changes for that group of switches.
Question 4
Case Study:
A hospital is overhauling its campus network using a FortiGate 1800F cluster and multiple stacks of FortiSwitch 448E models. The primary goal is to enforce strict segmentation and security while ensuring high performance for critical systems. The network must support three main user groups: Medical Devices (IoMT), Administrative Staff, and a public Guest Wi-Fi network.
Requirements:
IoMT Network (VLAN 100): Devices must be completely isolated from each other at Layer 2 to prevent lateral movement of malware. However, they all need to communicate with a central IoMT management server located in the data center. This traffic is latency-sensitive.
Admin Network (VLAN 200): Staff devices need to communicate with each other and with corporate servers. Access to the IoMT network is strictly forbidden.
Guest Network (VLAN 300): Guest devices must be isolated from each other and only have access to the internet. They must not be able to reach any internal network resources.
Current Plan: The administrator plans to use a single VDOM on the FortiGate and create separate VLANs for each group. All inter-VLAN routing will be handled by the FortiGate.
Given these stringent requirements, which design modification provides the most robust and efficient solution for the IoMT and Guest networks on the FortiSwitch access layer?
Answer and explanation
Correct answer: B
Private VLANs (PVLANs) are specifically designed for this use case. By configuring the IoMT and Guest VLANs as PVLANs, ports connected to end devices can be set as 'isolated'. This enforces strict Layer 2 isolation, preventing them from communicating with each other directly at the switch level. The uplink port to the central server and the FortiGate would be configured as 'promiscuous', allowing it to communicate with all isolated ports. This offloads the isolation task from the FortiGate, provides hardware-level enforcement, and is more secure and efficient than using ACLs for a large number of ports.
Question 5
An administrator is deploying a new fleet of VoIP phones and wants to leverage the FortiSwitch infrastructure to automatically provision them with the correct VLAN and Quality of Service (QoS) settings upon connection. Which protocol should be configured on the switch ports to achieve this?
Answer and explanation
Correct answer: B
LLDP-MED is an extension of LLDP specifically designed for media endpoint devices like VoIP phones. It allows the switch to automatically discover the device type and exchange information, including VLAN ID for voice traffic (Voice VLAN), QoS marking values (CoS/DSCP), and power requirements over Ethernet (PoE). This automates the provisioning process, ensuring voice traffic is correctly segregated and prioritized.
Question 6
A network operations team is experiencing intermittent high CPU utilization on a core FortiSwitch. They suspect an application is generating excessive broadcast or unknown unicast traffic, but enabling storm control has not logged any dropped packets. To identify the source traffic without the performance impact of a full packet capture (SPAN), what is the most appropriate monitoring feature to configure?
Answer and explanation
Correct answer: B
sFlow is designed for this exact purpose. It provides statistical sampling of network packets, which gives a clear view of traffic patterns, top talkers, and types of traffic (like broadcast or multicast) without the high overhead of mirroring every single packet. This allows the operations team to analyze traffic trends and identify the source of the excessive traffic on an external collector, making it the most efficient and appropriate tool for this troubleshooting scenario.
graph TD
subgraph Core FortiSwitch
A[Interface 1] --> S((sFlow Agent))
B[Interface 2] --> S
end
S -- Sampled Packets --> C[sFlow Collector/Analyzer]
subgraph NOC
C --> Admin[Admin Workstation]
end
Admin -->|Analyzes Traffic| C
Question 7
True or False: When configuring 802.1X port-based authentication on a FortiSwitch, a 'Guest VLAN' can be configured to automatically assign limited network access to endpoints that fail the RADIUS authentication process.
Answer and explanation
Correct answer: A
This statement is true. A key feature of robust 802.1X implementations, including on FortiSwitch, is the ability to define a Guest VLAN. If a device connects to an 802.1X-enabled port and fails to authenticate correctly against the RADIUS server, the switch can be configured to place the device into this pre-defined Guest VLAN. This provides a fallback mechanism, allowing the device limited access (e.g., internet only) instead of no access at all.
Question 8
A network architect is implementing Multiple Spanning Tree Protocol (MSTP) on a multi-tier FortiSwitch campus network to optimize load balancing for different VLANs. What is the most critical configuration parameter that must be identical across all switches participating in the same MSTP region to ensure they can interoperate correctly?
Answer and explanation
Correct answer: C
For switches to be considered part of the same MSTP region, they must share three identical attributes: the configuration name, the revision number, and the VLAN-to-instance mapping table. A hash of these values is included in the MSTP BPDUs. If a switch receives a BPDU with a different hash, it considers the sending switch to be in a different region. This consistency is absolutely critical for MSTP to function as intended.
Question 9
A network engineer is troubleshooting a FortiSwitch stack and needs to verify the health and statistics of the dedicated link between the two chassis in the MCLAG domain. Which CLI command will display this specific information?
diagnose switch mclag ______
Answer and explanation
Correct answer: D
The correct command is diagnose switch mclag icl. This command provides detailed information specifically about the Inter-Chassis Link (ICL), which is the critical connection that carries synchronization and data traffic between the two switches in an MCLAG pair. The output includes status, member ports, and traffic statistics, which are essential for troubleshooting MCLAG health.
Question 10
A financial services company is using FortiSwitch Private VLANs (PVLANs) to enforce strict Layer 2 isolation for servers belonging to different clients, even though they are in the same IP subnet. A shared backup server must be able to initiate connections to all isolated client servers. The client servers must not be able to communicate with each other. What PVLAN port type must be configured for the port connected to the shared backup server?
Answer and explanation
Correct answer: C
In a Private VLAN architecture, there are three port types. 'Isolated' ports can only communicate with promiscuous ports. 'Community' ports can communicate with each other and with promiscuous ports. 'Promiscuous' ports can communicate with all isolated and community ports within the PVLAN. Since the backup server needs to connect to all isolated client servers, its port must be configured as promiscuous.