Join the discussion
Question 5/27
While deploying FortiNAC-F devices in a 1+1 HA configuration, the administrator has chosen to use the shared IP address option.
Which condition must be met for this type of deployment?
Which condition must be met for this type of deployment?
Correct Answer: D
In a 1+1 High Availability (HA) deployment, FortiNAC-F supports two primary methods for management access: individual IP addresses or a Shared IP Address (also known as a Virtual IP or VIP). The Shared IP option is part of a Layer 2 HA design, which simplifies administration by providing a single URL or IP that always points to whichever appliance is currently in the "Active" or "In Control" state.
For a Shared IP configuration to function correctly, the Primary and Secondary administrative interfaces (port1) must be on the same subnet. This requirement exists because the Shared IP is a logical address that is dynamically assigned to the physical interface of the active unit. Since only one unit can own the IP at a time, both units must reside on the same broadcast domain (Layer 2) to ensure that ARP requests for the Shared IP are correctly answered and that the gateway remains reachable regardless of which unit is active. If the appliances were on different subnets (a Layer 3 HA design), a shared IP could not be used because it cannot "float" across different network segments; instead, administrators would need to manage each unit via its unique physical IP or use a FortiNAC Manager.
"For L2 HA configurations, click the Use Shared IP Address checkbox and enter the Shared IP Address information... If your Primary and Secondary Servers are not in the same subnet, do not use a shared IP address. The shared IP address moves between appliances during a failover and recovery and requires both units to reside on the same network." - FortiNAC-F High Availability Reference Manual: Shared IP Configuration.
For a Shared IP configuration to function correctly, the Primary and Secondary administrative interfaces (port1) must be on the same subnet. This requirement exists because the Shared IP is a logical address that is dynamically assigned to the physical interface of the active unit. Since only one unit can own the IP at a time, both units must reside on the same broadcast domain (Layer 2) to ensure that ARP requests for the Shared IP are correctly answered and that the gateway remains reachable regardless of which unit is active. If the appliances were on different subnets (a Layer 3 HA design), a shared IP could not be used because it cannot "float" across different network segments; instead, administrators would need to manage each unit via its unique physical IP or use a FortiNAC Manager.
"For L2 HA configurations, click the Use Shared IP Address checkbox and enter the Shared IP Address information... If your Primary and Secondary Servers are not in the same subnet, do not use a shared IP address. The shared IP address moves between appliances during a failover and recovery and requires both units to reside on the same network." - FortiNAC-F High Availability Reference Manual: Shared IP Configuration.
Add Comments
- Other Question (27q)
- Q1. During an evaluation of state-based enforcement, an administrator discovers that ports tha...
- Q2. Refer to the exhibit. (Exhibit) After a successful layer 2 poll, two hosts were learned on...
- Q3. Which two requirements must be met to set up an N+1 HA cluster? (Choose two.)...
- Q4. Which two actions must the administrator perform to allow FortiNAC-F to process incoming s...
- Q5. While deploying FortiNAC-F devices in a 1+1 HA configuration, the administrator has chosen...
- Q6. When creating a user or host profile, which three criteria can you apply? (Choose three.)...
- Q7. Refer to the exhibit. (Exhibit) If a host is connected to a port in the Building 1 First F...
- Q8. Refer to the exhibit. (Exhibit) An administrator wants to ensure that guest accounts creat...
- Q9. Refer to the exhibits. (Exhibit) What would happen if the highlighted port with connected ...
- Q10. While troubleshooting a network connectivity issue, an administrator determines that a dev...
- Q11. When configuring FortiNAC-F to manage FortiGate VPN users, an endpoint compliance policy m...
- Q12. An administrator wants to control user access to corporate resources by integrating FortiN...
- Q13. An administrator wants FortiNAC-F to pass firewall tags to FortiGate to leverage dynamic a...
- Q14. Two FortiNAC-F devices have been configured as a 1 + 1 HA pair. The primary server went of...
- Q15. Refer to the exhibit. (Exhibit) An administrator has configured the DHCP scope for a regis...
- Q16. An organization wants to add a FortiNAC-F Manager to simplify their large FortiNAC-F deplo...
- Q17. When working with a FortiNAC-F Manager and cluster management, what will occur when a clus...
- Q18. Refer to the exhibits. (Exhibit) An administrator is troubleshooting visibility issues on ...
- Q19. An administrator wants to create a conference manager administrator account but would like...
- Q20. Refer to the exhibit. (Exhibit) What would FortiNAC-F generate if only one of the security...
- Q21. Refer to the exhibit. (Exhibit) An administrator wants to use FortiNAC-F to automatically ...
- Q22. What must an administrator configure to allow FortiNAC-F to process incoming syslog messag...
- Q23. When preparing network infrastructure devices for visibility, what are the two main advant...
- Q24. A user was attempting to register their host through the registration captive portal. Afte...
- Q25. When managing multiple FortiNAC-F CAs with a FortiNAC-F Manager, how is endpoint informati...
- Q26. Refer to the exhibit. A FortiNAC-F N+1 HA configuration is shown. (Exhibit) What will occu...
- Q27. An administrator wants to build a security rule that will quarantine contractors who attem...
[×]
Download PDF File
Enter your email address to download Fortinet.NSE5_FNC_AD_7.6.v2026-07-18.q27.pdf
