2 x FGT100Ds connecting to switch stack
- April 5, 2016
- 1 reply
- 9722 views
We currently have 2 x Fortigate 100Ds setup in HA connecting to a single switch to which several servers are attached. On the Fortigate, port1 is our WAN, port2 is our LAN. Because of the spec of the current switch, we have VLAN sub interfaces on port2 corresponding to each server. Everything is working OK at the moment.
We want to build some redundancy in for the switch though as a) it's a single point of failure and b) recovering it in the event of a failure would be quite time consuming. We've purchased two HP 2920s which I've stacked, and I'm trying to establish how the configuration should look before I arrange travel and server downtime.
I haven't built a stacked switch before, so I've mocked up a diagram of how it might look and attached it here.
Is the layout consistent with anyone else's experience?
On the Fortigate, do I need to create a hardware switch consisting of port2 and port3 on the FGT? If yes, that means blowing away all objects in the config referring to port2 and replacing it with the name of the new hardware switch? :(
Or can I just enable LACP on the Fortigate on port2 and port3 and simultaneously enable LACP on the switch on ports 1/47, 1/48 and 2/47 and 2/48?
The servers are mostly Windows 2012 with teamed NIC configurations; has anyone had any pitfalls with this sort of setup?
HA mode is A-A
Firmware version: v5.2.4,build688
