🎧 New: AI-Generated Podcasts Turn your study notes into engaging audio conversations. Learn more

FortiGate Active-Passive High Availability (H-A) Quiz
30 Questions
1 Views

FortiGate Active-Passive High Availability (H-A) Quiz

Created by
@VisionarySugilite

Podcast Beta

Play an AI-generated podcast conversation about this lesson

Questions and Answers

Which component is required in the environment for an active-passive deployment of FortiGate VMs?

  • One internal Azure standard load balancer
  • Three public IPs
  • One V-NET with one protected subnet (correct)
  • One external Azure standard load balancer
  • What is the purpose of the external Azure standard load balancer in the FortiGate setup?

  • To configure S-NAT for North-South traffic
  • To handle traffic failover using a health probe
  • To provide communication with the internet (correct)
  • To receive all internal traffic and forward it to its destination
  • How many public IPs are used in the FortiGate setup for management access?

  • Four
  • Three
  • Two (correct)
  • One
  • What is the purpose of UDRs in the FortiGate setup?

    <p>To redirect traffic to the internal load balancer</p> Signup and view all the answers

    How do the FortiGate VMs communicate with each other in the active-passive deployment?

    <p>Using the unicast FGCP H-A protocol</p> Signup and view all the answers

    What is the recommended method to avoid asymmetric routing in the FortiGate setup?

    <p>Configuring S-NAT for North-South traffic</p> Signup and view all the answers

    What is required to deploy FortiGate VMs for Azure Autoscale?

    <p>Virtual machine scale sets</p> Signup and view all the answers

    What does the Azure function app handle in the FortiGate Autoscale deployment?

    <p>All of the above</p> Signup and view all the answers

    What information is stored in the tables of Cosmos DB in the FortiGate Autoscale deployment?

    <p>All of the above</p> Signup and view all the answers

    What is one of the options to create a site-to-site IPsec VPN connection with Azure using FortiGate?

    <p>FortiGate in your local network</p> Signup and view all the answers

    Which component is required for the FortiGate Active-Passive H-A with Fabric Connector deployment?

    <p>One V-NET with one protected subnet</p> Signup and view all the answers

    What is the purpose of the first public IP in the FortiGate Active-Passive H-A with Fabric Connector deployment?

    <p>Access through the active FortiGate</p> Signup and view all the answers

    What is the role of the SDN fabric connector in the FortiGate Active-Passive H-A with Fabric Connector deployment?

    <p>To facilitate failover</p> Signup and view all the answers

    What protocol do the two FortiGate VMs use to synchronize the configuration in the active-passive deployment?

    <p>FortiGate Clustering Protocol (FGCP)</p> Signup and view all the answers

    Why is the active-passive deployment with the Azure load balancer the preferred option?

    <p>Both faster failover time and easier management</p> Signup and view all the answers

    What must be done after the deployment of the FortiGate Active-Passive H-A with Fabric Connector?

    <p>Apply the Reader role to the Azure Subscription</p> Signup and view all the answers

    What is the purpose of the two additional public IPs in the FortiGate Active-Passive H-A with Fabric Connector deployment?

    <p>Management access</p> Signup and view all the answers

    What is the main advantage of using the FortiGate Active-Passive H-A with Fabric Connector deployment?

    <p>Customizable traffic inspection</p> Signup and view all the answers

    Why is the FortiGate Active-Passive H-A with Fabric Connector deployment not used very frequently?

    <p>Longer failover time</p> Signup and view all the answers

    What is the purpose of the user-defined routes (UDRs) in the FortiGate Active-Passive H-A with Fabric Connector deployment?

    <p>To customize traffic routing</p> Signup and view all the answers

    Which two options are available for establishing a site-to-site IPsec VPN with your Azure network?

    <p>FortiGate in your local network and Azure VPN Gateway on the Azure side</p> Signup and view all the answers

    What is the recommended solution for ensuring the best protection and avoiding the administrative burden of managing multiple VPN platforms?

    <p>FortiGate in your local network and FortiGate VM on the Azure side</p> Signup and view all the answers

    What can you deploy on either end of the connection for scenarios that require high availability?

    <p>FortiGate H-A clusters</p> Signup and view all the answers

    What can you use to establish a site-to-site IPsec VPN with your Azure network if you want similar results with either option?

    <p>FortiGate in your local network and FortiGate VM on the Azure side</p> Signup and view all the answers

    Which option is recommended for ensuring the best protection and avoiding the administrative burden of managing multiple VPN platforms?

    <p>FortiGate in your local network and FortiGate VM on the Azure side</p> Signup and view all the answers

    What is the purpose of deploying FortiGate H-A clusters on either end of the connection?

    <p>To provide high availability</p> Signup and view all the answers

    Which option is recommended for scenarios that require high availability?

    <p>FortiGate H-A clusters</p> Signup and view all the answers

    Which option is recommended for establishing a site-to-site IPsec VPN with your Azure network if you want the best protection and want to avoid managing multiple VPN platforms?

    <p>FortiGate in your local network and FortiGate VM on the Azure side</p> Signup and view all the answers

    What is the purpose of using FortiGate on both ends of the connection?

    <p>To ensure the best protection and avoid the administrative burden of managing multiple VPN platforms</p> Signup and view all the answers

    What is the purpose of using FortiGate in your local network and FortiGate VM on the Azure side?

    <p>To establish a site-to-site IPsec VPN with your Azure network</p> Signup and view all the answers

    More Quizzes Like This

    Use Quizgecko on...
    Browser
    Browser