A solutions architect is designing an ADVPN topology with two hubs for redundancy. BGP is the chosen routing protocol. To prevent spokes from becoming a transit for traffic between the two hubs, a specific BGP community is typically used. Which BGP community should be advertised from the spokes to the hubs to achieve this?
Answer and explanation
Correct answer: D
In a dual-hub ADVPN setup, spokes should advertise their prefixes to both hubs with the 'no-export-subconfed' (or simply 'no-export') community. When a hub receives a route from a spoke with this community, it uses it for its own routing table but does not re-advertise it to the other hub. This prevents the spokes from becoming transit ASs and avoids routing loops or suboptimal routing between data centers.
Question 2
A FortiGate is configured in an Active-Passive FGCP cluster. During a scheduled failover test, the administrator notices that all existing connections are dropped and must be re-established. Analysis of the cluster configuration shows that session pickup is enabled. What is the most likely reason for the sessions being dropped despite session pickup being enabled?
Answer and explanation
Correct answer: B
Session pickup synchronizes session information for flow-based inspected traffic. However, sessions handled by a proxy (e.g., proxy-based web filtering or explicit proxy) are terminated on the primary FortiGate and new sessions are created. These proxy sessions are not synchronized to the secondary unit by default. Upon failover, the proxy daemon on the newly active unit has no state for these connections, causing them to be dropped.
Question 3
A network engineer is troubleshooting an OSPF issue where a FortiGate is not forming an adjacency with a Cisco router. The FortiGate is in OSPF area 1, which is configured as a Not-So-Stubby Area (NSSA). The Cisco router is in the same area but is configured as a standard, non-stub area. Both devices are on the same subnet and can ping each other. What is causing the adjacency to fail?
Answer and explanation
Correct answer: B
For an OSPF adjacency to form, several parameters in the OSPF Hello packet must match between neighbors. One of the critical parameters is the area type (Stub Flag). If one router is configured for a standard area and the other is configured for a special area type like NSSA, the Hello packets will be considered incompatible, and the adjacency will not progress past the Init state.
Question 4
A security administrator needs to create a custom IPS signature to detect and block the string "confidential-project-alpha" in plain text HTTP traffic. The traffic could be in either the client request or the server response. Which of the following custom signature syntaxes is the most effective and efficient way to achieve this?
Answer and explanation
Correct answer: B
This is the correct syntax. The --flow from_client,from_server keyword ensures the signature engine inspects traffic in both directions. The --service HTTP keyword optimizes the signature by telling the engine to only inspect decoded HTTP traffic, which is much more efficient than inspecting all TCP traffic on port 80. The --pattern keyword specifies the string to match.
Question 5
Multiple answers
During a security audit, it was discovered that a junior administrator configured a new ADOM on FortiManager but assigned a FortiOS version of 6.4, while all the FortiGate devices to be managed are running FortiOS 7.2. What are the primary implications of this misconfiguration? (Select TWO)
Answer and explanation
Correct answers: B, D
Question 6
True or False: When using FortiManager in a workspace mode configuration, an administrator must lock an ADOM before making any configuration changes to policy packages or objects within that ADOM.
Answer and explanation
Correct answer: A
Workspace mode is designed to prevent multiple administrators from making conflicting changes simultaneously. Before any modifications can be made within an ADOM (such as editing policies, objects, or device settings), the administrator must explicitly lock that ADOM. This ensures a safe and controlled change management process.
Question 7
An organization uses two FortiGate devices in different data centers, managed by a third-party load balancer for active/active processing. They need to ensure that if one FortiGate fails, user sessions are seamlessly transferred to the other without requiring re-authentication. A traditional FGCP cluster is not feasible due to the network architecture. Which Fortinet technology is designed for this specific scenario?
Answer and explanation
Correct answer: C
FortiGate Session Life Support Protocol (FGSP) is the correct technology. It is specifically designed to synchronize sessions between two or more standalone FortiGate devices. This allows a load balancer to distribute traffic, and if one device fails, the other can take over the sessions without interruption because it has a copy of the session table.
Question 8
A consultant is reviewing a BGP configuration on a FortiGate that is multihomed to two different ISPs. The company wants to ensure that all outbound traffic prefers the primary ISP link, but can automatically fail over to the secondary ISP. The primary ISP connection has higher bandwidth and lower latency. Which BGP attribute should be manipulated on the inbound route maps from the ISPs to achieve this routing policy?
Answer and explanation
Correct answer: D
Local Preference is the standard attribute used to influence outbound traffic path selection within a single Autonomous System (AS). By setting a higher Local Preference value (default is 100) on routes received from the primary ISP, the FortiGate will prefer that path for all outbound traffic. This attribute is propagated to all iBGP peers within the AS, ensuring consistent exit point selection.
Question 9
Case Study:
A large enterprise, FinCorp, operates a primary data center and a disaster recovery (DR) site, each with a FortiGate cluster. They have a requirement for deep SSL inspection for all outbound web traffic for compliance reasons. To reduce the load on the individual FortiGates and centralize certificate management, they want to offload the SSL inspection to a dedicated appliance.
All outbound traffic from the user network is routed to the primary FortiGate cluster. The dedicated SSL inspection appliance is located in a separate security zone. The FortiGates are responsible for applying web filtering, IPS, and application control after the traffic has been decrypted.
The security architect has proposed a solution where the FortiGate forwards traffic to the SSL inspection appliance, receives the decrypted traffic back, applies security profiles, and then forwards it to the internet. The following diagram illustrates the intended logical traffic flow:
Which FortiOS feature must be configured on the FortiGate to support this design?
Answer and explanation
Correct answer: D
This scenario describes a classic SSL offloading use case. The FortiGate can be configured as a transparent web proxy. Within the web proxy profile, you can enable SSL offloading, which directs HTTPS traffic to an external appliance for decryption. The FortiGate then receives the decrypted HTTP traffic, applies the necessary security profiles (Web Filter, IPS, etc.), and routes it out. This feature is designed specifically for integrating with third-party SSL inspection solutions.
Question 10
An administrator is attempting to establish a certificate-based IKEv2 IPsec tunnel between two FortiGates. Phase 1 fails to come up. The debug output on the initiator shows the message "received peer certificate but it is not trusted". The administrator has confirmed that both FortiGates have their own signed local certificates and the CA certificate for the peer. What is a common cause for this error?
Answer and explanation
Correct answer: A
When using certificate authentication, the FortiGate must both trust the CA that signed the peer's certificate AND verify the peer's identity. A common mistake is a mismatch between the configured peer ID (e.g., a specific FQDN or IP address) and the identity contained within the peer's certificate (e.g., the Subject or Subject Alternative Name field). If these do not match based on the peerid setting, the FortiGate will not trust the certificate for authentication, even if the issuing CA is trusted.