Technical Tip: Use of HA active-passive FortiGate Cluster instead of two stand-alone FortiGates to avoid asymmetric routing
| Description | This article describes that sometimes, redundancy is required in a network. While two stand-alone firewalls can provide redundancy, asymmetric routing is required in this stand-alone design to ensure no packets are dropped due to session issues.
While asymmetric routing is a good workaround, it is not the best security practice, as some packets are not subjected to UTM checks. |
| Scope | FortiGate. |
| Solution | In HA active-passive HA setups, the standby firewall is not actively processing traffic, so asymmetric routing is unlikely. To configure an HA active-passive HA setup, refer to the relevant documentation.
Change the FortiOS version as required. For example, HA active-passive cluster setup:
Note:
|

