Skip to main content
kmak
Staff
Staff
October 18, 2024

Technical Tip: How to configure Health Check Monitoring policy for FortiAnalyzer as the backend real server of a Virtual Server

  • October 18, 2024
  • 0 replies
  • 875 views
Description This article describes the health check configuration for FortiAnalyzer as the backend real server of a Virtual Server.
Scope FortiADC.
Solution

Prerequisites:

  • FortiAnalyzer is a real server pool member of FortiADC.
  • FortiAnalyzer version v7.4.2 or above.

 

Explanations and Configurations:

  1. On some occasions, the FortiAnalyzer is proxied through FortiADC and the FortiAnalyzer IP will be configured as the Real Server Pool of a Virtual Server in FortiADC. The default HTTPS health check monitoring of FortiADC would fail to connect and check the HTTPS health status of the FortiAnalyzer.
                                           
kmak_0-1729223946951.jpeg

 

  1. Since the FortiAnalyzer version 7.4.x and above, the supported SSL cipher list of the HTTPS protocol has been further restricted. The list of supported cipher lists can be referred to in the screenshot.
                                                                               

    kmak_1-1729223946961.jpeg

     

     

  2. FortiADC's default HTTPS monitoring policy does not include the SSL cipher list that is supported by FortiADC which causes the HTTPS connection error.
                                                                                              

    kmak_2-1729223946968.jpeg

     

     

  3. In the FortiADC health check policy dedicated to FortiAnalyzer, select to enable the 2 ciphers 'ECDHE-RSA-AES256-GCM-SHA384” and “ECDHE-RSA-AES128-GCM-SHA256'. De-select the unsupported TLS protocol and other SSL cipher lists since they are no longer required. It is also important to make sure the Status Code is ‘301’.
                                                                                                   

    kmak_3-1729223946975.jpeg

     

     

  4. Update the FortiAnalyzer Real Server Pool Health Check List settings to use the dedicated health check monitoring policy for FortiAnalyzer.
                                                                                                 

    kmak_4-1729223946980.jpeg

                                                             

     

  5. The FortiADC Health Check Event log should have the event of the FortiAnalyzer Real Server Pool member being identified as UP after configuring the health checklist.               

                                                                                  
kmak_5-1729223946983.jpeg

 

Related document:

Configuring health checks