An administrator has configured two FortiGate devices for an HA cluster. While testing HA failover, the administrator notices that some of the switches in the network continue to send traffic to the former primary device. The administrator decides to enable the setting link-failed-signal to fix the problem. Which statement about this setting is true?
A.
It sends an ARP packet to all connected devices, indicating that the HA virtual MAC address is reachable through a new master after a failover.
B.
It sends a link failed signal to all connected devices.
C.
It disabled all the non-heartbeat interfaces in all HA members for two seconds after a failover.
D.
It forces the former primary device to shut down all its non-heartbeat interfaces for one second, while the failover occurs.
Refer to the exhibit, which shows a FortiGate configuration.
An administrator is troubleshooting a web filter issue on FortiGate. The administrator has configured a web filter profile and applied it to a policy; however, the web filter is not inspecting any traffic that is passing through the policy. What must the administrator change to fix the issue?
A.
The administrator must increase webfilter-timeout.
B.
The administrator must disable webfilter-force-off.
C.
The administrator must change protocol to TCP.
D.
The administrator must enable fortiguard-anycast.
Refer to the exhibit, which contains the output of get system ha status. Which two statements about the output are true? (Choose two.)
A.
The slave configuration is synchronized with the master.
B.
port7 is used as the HA heartbeat on all devices in the cluster.
C.
Master is selected based on the priority configured under config system ha.
D.
The HA management IP is 169.254.0.2.
Answer:
BC
User Votes:
A
50%
B
50%
C
50%
D
50%
Discussions
0/ 1000
Question 15
Refer to the exhibit, which contains a TCL script configuration on FortiManager.
An administrator has configured the TCL script on FortiManager, but failed to apply any changes to the managed device after being executed. Why did the TCL script fail to make any changes to the managed device?
A.
Changes in an interface configuration can only be done by CLI script.
B.
The TCL script must start with #include <>.
C.
Incomplete commands are ignored in TCL scripts.