Technical Tip: Configuring Geo-Redundant HA with VRRP Failover on FortiManager
| Description | This article describes the configuration of a simple Geo-Redundant High Availability (HA) cluster using two FortiManager-VM64 instances located in different subnets. The design highlights the use of VRRP failover mode with a dummy Virtual IP (VIP), unicast communication between cluster nodes, and specific certificate requirements. It also outlines considerations for deployments where firewalls exist between FortiManager devices, managed FortiGate devices, and administrative users, ensuring required communication paths are permitted for proper cluster operation and management. |
| Scope | FortiManager-VM64 v7.6.6 and later. |
| Solution | Diagram.
Components and requirements:
Connectivity: Ensure the default gateway is correctly configured on both instances to allow the unicast packets to route between both subnets.
If a firewall is introduced between the management network (where FortiManager administrators are located) and either Subnet A / Subnet B (managed FortiGates / FortiManager devices), the following must be allowed:
|

