How Do You Segment Department Traffic Across an Active FTD HA Pair?
Within an organization’s high availability environment where both firewalls are passing traffic, traffic must be segmented based on which department it is destined for. Each department is situated on a different LAN. What must be configured to meet these requirements?
Community Votes
50% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests whether you can distinguish logical firewall segmentation in an HA pair from interface or link redundancy, with the trap being that active/standby HA is mistaken for a design that lets both firewalls forward traffic.
In an FTD high availability deployment where both chassis must pass traffic, multi-instance firewalls let you segment each department's LAN into separate container instances. This page confirms why option D is correct and why active/standby, redundant interfaces, and EtherChannel do not provide the required segmentation.
Most learners choose active/standby HA (C) because the scenario says high availability, but active/standby keeps one chassis idle and does not create per-department security domains.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Multi-instance firewalls (container instances) create multiple independent logical FTDs on the same hardware, each with its own interfaces, routing table, and security policies, so each department LAN can be placed in its own instance. In a multi-instance HA deployment, two chassis each run multiple instances; active/standby roles are assigned per instance, so one chassis can actively forward instance 1 while the peer actively forwards instance 2. This satisfies the requirement that both firewalls pass traffic while traffic is segmented by department. Cisco's FTD multi-instance HA documentation describes exactly this two-chassis, multiple-instance layout. Therefore D is the only option that combines segmentation with both chassis forwarding.Why the Other Options Are Wrong
A. Redundant interfaces provide physical interface failover, not separation of department traffic; they would simply give one logical firewall a backup link. B. Spanned EtherChannel (or EtherChannel clustering) aggregates links for bandwidth and path redundancy, but it does not create per-department security contexts or instances. C. Active/standby HA is the classic HA mode, but only the active firewall passes traffic, which directly contradicts "both firewalls are passing traffic" and does not by itself segment departments. None of A, B, or C deliver the required logical separation while keeping both chassis active.Community Comment Notes
gwb made the key distinction that "segmentation means separation," adding that a redundant interface is a backup and that active/standby "does NOT allow both firewalls passing traffic." tinyJoe called it a "very unclear question" but selected D and pointed to the Cisco document on configuring FTD multi-instance high availability, where two FTDs each run two instances. d0980cc chose C and suggested VLAN subinterfaces, but subinterfaces alone still leave one chassis forwarding unless you add multi-instance contexts. The comment thread therefore supports D once the active/active wording is taken literally.Official Reference
Exam Strategy
When both HA peers must pass traffic and departments need separate security domains, think logical segmentation (multi-instance/container instances) rather than classic active/standby. Read the stem literally: "both firewalls are passing traffic" rules out active/standby as the answer to the requirement.
Frequently Asked Questions
Why isn't active/standby HA enough for department segmentation?
Active/standby keeps only one chassis forwarding at a time, so it fails the requirement that both firewalls pass traffic and provides no separate logical firewall per department.
Do VLAN subinterfaces alone satisfy the segmentation requirement?
No; subinterfaces can separate traffic on one FTD, but the scenario needs independent firewall instances so each department's policy and forwarding domain are isolated.