925-201b Principles of Network Security and FortiGate Configurations Exam Actual Test


Fortinet ™

925-201b Principles of Network Security and FortiGate Configurations



Note 1: 925-201b Exhibit and all related diagrams are not shown in demo questions.
Note 2: 925-201b Answers are not shown in demo questions.
Exhibits and Answers are only provided in the Full Version.


Demo Question 16.


Which of the following statement is true about HA heartbeat device ?

A. only one interface can be configured as heartbeat device
B. up to 2 interfaces can be configured as heartbeat device
C. you can configure multiple heartbeat device , any physical interface can be heartbeat device
D. you can configure multiple heartbeat device , any physical interface & vlan sub-interface can be heartbeat device


Display Answer


Purchase Full Version:


925-201b Printable PDF Prep Guide $49.95 BUY NOW!

925-201b Test Simulation Engine $69.95 BUY NOW!

925-201b PDF & Test Simulation Engine $99.95 BUY NOW!




Answer: C

Explanation: Heartbeat devices A heartbeat device is an Ethernet network interface in a cluster that is used by the FGCP for HA heartbeat communications between cluster units. You can configure multiple network interfaces to be heartbeat devices. An interface becomes a heartbeat device when it is assigned a heartbeat device priority. The HA configuration in Figure 2 shows port3 and port4/ha configured as heartbeat devices. Figure 2: Example FortiGate-3000 heartbeat device configuration The heartbeat device with the highest priority is the active heartbeat device. In Figure 2, port4/ha is the active heartbeat device. The active heartbeat device sends and receives all heartbeat communications. If the active heartbeat device fails or is disconnected on one or more of the cluster units, the heartbeat device with the next highest priority becomes the active heartbeat device. This is called heartbeat device failover. Heartbeat device failover occurs transparently, without interrupting the communication sessions being processed by the cluster and without affecting cluster synchronization. By default, for all FortiGate units, two interfaces are configured to be heartbeat devices. The active heartbeat device has a priority of 100. A second, or backup heartbeat device has a priority of 50. The fortiGate-300,400,500,800,1000,3000,and 3600 HA interfaces has the highest heartbeat device priority. The fortiGate-60,100,200,and the Fortiwifi60 DMZ interface has the highest interfaces has the highest heartbeat device priority. The FortiGate-100A and 200A DMZ2 interface has the highest heartbeat device priority. The FortiGate-300A and 400A, and500A port4 interface has the highest heartbeat device priority. The FortiGate-4000 out of band management interface has the highest heartbeat device priority. The FortiGate-5000 has two dedicated HA heartbeat device (Port 9 and Port 10). Port 10 has the highest heartbeat device priority. You can change the heartbeat device configuration as required. All interfaces can be assigned different heartbeat priorities. You can also configure only one interface to be a heartbeat device. You can set the heartbeat device priority for each interface to any number between 1 and 512. In all cases, the heartbeat device with the highest priority is used for all HA heartbeat communication. If this interface fails or becomes disconnected, the interface with the next highest priority handles all of the heartbeat traffic. For the HA cluster to function correctly, at least one interface must be a heartbeat device. Also the heartbeat devices of all cluster units must be connected together. If heartbeat communication is interrupted and cannot fail over to a second heartbeat device, the cluster stops processing traffic. Heartbeat device IP addresses You do not need to assign IP addresses to the heartbeat device interfaces for them to be able to process heartbeat packets. The FGCP assigns virtual IP addresses to the heartbeat device interfaces. The primary unit heartbeat device IP address is 10.0.0.1. Subordinate units are assigned heartbeat device IP addresses 10.0.0.2, 10.0.0.3, and so on. For best results, isolate the heartbeat devices from your user networks by connecting the heartbeat devices to a separate switch that is not connected to any network. If the cluster consists of two FortiGate units you can connect the heartbeat device interfaces directly using a crossover cable. Heartbeat packets contain sensitive information about the cluster configuration. Heartbeat packets may also use a considerable amount of network bandwidth. For these reasons, it is preferable to isolate heartbeat packets from your user networks. Both HA heartbeat and data traffic are supported on the same FortiGate interface. In NAT/Route mode, if you decide to use the heartbeat device interfaces for processing network traffic or for a management connection, you can assign the interface any IP address. In Transparent mode, you can connect the interface to your network and configure management access to it. These configurations do not affect heartbeat traffic or the heartbeat device IP addresses.



  • Based on the latest 925-201b exam objectives!
  • Designed like actual 925-201b exam questions!
  • 100% Verified Realistic 925-201b Exam Questions and Answers!
  • Exhibits, Drag&Drop and Simulation 925-201b Questions Included!
  • Constantly Updated Guide to Reflect the Current 925-201b Exams!
  • Detailed Explanations for Most Guide Practice Exams!
 Sponsored Links
Japan Exam



MCED
1D0-430 1D0-435
1D0-437 1D0-441
1D0-442 1D0-538

$179 Get Detail

SCSI
310-330
$49.95 Get Detail

MCSE 2003 Security
70-270 70-290
70-291 70-292
70-293 70-294
70-298 70-299

$239 Get Detail

LPI 2
117-201 117-202

$59 Get Detail

SCSSSE
310-880
$49.95 Get Detail


London, UK
First class site! Just passed 70-290 and achieved my MCSE & MCSA. ...


England
Many thanks to your complete solution in 3Com Test Simulation Engine, Study Guides and PDF practice exams which are very ...


NY, USA
I wanted to take a few minutes to thank EliteCertify for passing 3 exams towards my MCSE. ...





Keyword
This site is both PayPal and VeriSign Verified. 128-bit SSL Encryption!
More questions about Order Security?