Best Practices for FortiGate HA Pair Setup with FortiSwitch FS148F and FS124F
Hello Fortinet Community,
I'm seeking advice on the best practice for setting up two FortiGate 121G units in an active-passive HA pair configuration, alongside two FortiSwitch models FS148F and FS124F (does not support MCLAG). I'm currently evaluating two potential topologies and would appreciate your insights on both, particularly around VLAN configurations and any relevant design considerations.
Here are the two topology options I'm considering:
Daisy-Chained Topology:
In this scenario, the two FortiGate units in HA mode will be connected to a daisy chain of FortiSwitches (FS148F and FS124F). The switches would be stacked for redundancy.Mesh Topology:
Each FortiGate in the HA pair would be connected directly to both FortiSwitches. This creates a more distributed setup with each switch directly connected to each firewall for greater redundancy.
Questions:
- How would VLAN management differ between the daisy-chained and mesh topologies?
- What would be the most efficient way to handle VLANs with this setup to ensure optimal traffic flow and minimal complexity?
- Are there any potential performance bottlenecks or limitations with either of these designs?

