Skip to main content
adebeer_FTNT
Staff
Staff
November 17, 2022

Technical Tip: More information about FortiGate Session Life Support Protocol (FGSP)

  • November 17, 2022
  • 0 replies
  • 3952 views
Description This article provides additional information about FortiGate Life Support Protocol.
Scope FortiGate v6.4 and v7.0.
Solution

What FGSP is:

FortiGate Session Life Support Protocol distributes sessions between 2 entities. In the defined configuration from the ticket, it is 2 standalone FortiGates. In the case of one FortiGate failure, the session failover occurs, and active sessions fail over to the working peer. In this case, the external routers must detect the failover and redistribute the sessions to the active peer. When using this session sync, it's important to ensure that the active device has enough processing power to handle all of the sessions if a failover occurs.

 

Determining whether both devices are active in an FGSP cluster:

Each device communicates with its own IP address. Interface IP addresses are unique, but VLANs, LAGS etc must have the same name on the devices.


The requirements for FGSP:

All devices in the cluster running FGSP must be the same hardware model and must be running the same firmware.


Which sessions can be synced:

The sessions that can be synced are IPv4 and IPv6 TCP, UDP, ICMP expectation sessions, NAT sessions, asymmetric sessions, IKE routes, and IPSec tunnels. It's possible to manually decide and configure which sessions to sync.


Which sessions will have issues during failover:

Sessions that have Flow or Proxy-based security profiles are not expected to work properly if the traffic in the session is load-balanced across several FortiGates in either direction. However, flow-based inspection will work in an FGSP deployment. IPsec keys and other runtime data are synced: IPSec tunnels will be re-established, but all existing tunnel sessions must be restarted. Interfaces on the FortiGates that are tunnel endpoints must have the same IP address. External routers need to load balance the IPsec tunnel session to the FortiGates.

FGSP's job is to keep the tunnel state (IKE SA, IPsec SA, keys, SPI, etc.) mirrored across cluster members so the passive node can take over without forcing the remote peer to re-negotiate from scratch.


Explaining config sync:

It is possible to enable config sync in an FGSP deployment. However, note the following limitations:

  • Network interruptions will occur during firmware upgrade, meaning all members in the standalone-config-sync group will upgrade simultaneously.
  • Unwanted configuration parameters may be synced.
  • The wrong primary device might be used accidentally. It is important to select the correct device as the primary device.

Due to these limitations, it is recommended to sync the configuration between the cluster devices in another way.

 

The protocols and ports used to sync the sessions:

The FortiGate's HA Heartbeat listens on the following ports using these protocols: TCP/703, TCP/23, or ETH Layer 2/8890 on port 6066. Session sync packets will use ETH 2/8892.


The parameters necessary to use the FGSP protocol:

To use FGSP, the following must be configured:

  • Parameters to find the peer to communicate with to send/receive the sessions.
  • Parameters to send the sessions in its session table to sync with its peers and to maintain the synced session.
  • Parameters to receive the sessions from the peer and maintain the sessions table in synch with the received sessions.

 

User traffic impact when the session sync is slower than the server response time:

This can happen when only user-space session sync (IP-peer UDP 708) is used. To avoid this, use kernel session sync with dedicated session-sync-dev and layer2-connection enabled.

 

Related documents:

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.