Cable FortiAnalyzer directly to FG HA pair?
We are installing a new HA pair of 501E's (v5.6) to replace some older FG's, and we're adding a FAZ 400E (v6.0) to the mix. No FAZ installed previously. I have one FAZ port on our mgmt VLAN and I can access it fine. I plan to use a separate FAZ port to receive the logging from the FG(s). Is there any way to cable the FAZ directly to the HA pair to receive logging? E.g., port10 on first 501E to FAZ port3 and port10 on second 501E to FAZ port4.
I don't see any internal switching capability in the FAZ to put two ports together with a single IP address. I don't see any layer 2 protocol options between FAZ & FG either. I don't have any other bright ideas. Has anyone attempted this with success?
If we use only one FAZ port then whatever switch module that port connects to is a single point of failure. All other devices of this significance in our network have redundant connections to different switch modules. We don't see the need for a 2nd FAZ as we will also be logging to the 501E internal disks and a separate syslog server too. I just want this cabling redundancy if the device design allows for it. Perhaps I should have thought of this before choosing the appliance over the VM license, but let's not dwell on that!
Thanks,
Fred
