Skip to main content
AEK
SuperUser
SuperUser
October 23, 2023
Solved

FGCP over FGSP sharing HA ports

  • October 23, 2023
  • 3 replies
  • 2292 views

Hello

We have 2 pairs of FortiGates, FGCP over FGSP

What can be the side effects of having HA1 & HA2 ports for synchronizing both FGSP and FGCP at the same time?

Best answer by xshkurti

@AEK 


FGCP is a Layer 2 heartbeat that specifies how FortiGate units communicate in an HA cluster and keeps the cluster operating.


Whilst session synchronization between FGSP members uses an L3 connection over the peer IP by default. So HA1 and HA2 can have IP addresses configured and that will be used by FGSP members.

So technically there is no issue using HA1 and HA2 for both type of synch. The problem i see is in the design. If HA1 and HA2 for some reason go down, you will lose both synchronizations, and you will have strange failover situations (probably even split-brain) This is because HA1 and HA2 are recommended to be directly connected between 2 fortigates. But if you use HA1 and HA2 even for FGSP, i thing that you will have to use switch and router devices in between. 

Knowing this, the problem is all design, not technical.

 

3 replies

Anthony_E
Staff
Staff
October 26, 2023

Hello AEK,


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Best Regards
Anthony_E
Staff
Staff
October 30, 2023

Hello AEK,

 

We are still looking for someone to help you.

We will come back to you ASAP.


Regards,

Best Regards
xshkurti
Staff
xshkurtiAnswer
Staff
October 30, 2023

@AEK 


FGCP is a Layer 2 heartbeat that specifies how FortiGate units communicate in an HA cluster and keeps the cluster operating.


Whilst session synchronization between FGSP members uses an L3 connection over the peer IP by default. So HA1 and HA2 can have IP addresses configured and that will be used by FGSP members.

So technically there is no issue using HA1 and HA2 for both type of synch. The problem i see is in the design. If HA1 and HA2 for some reason go down, you will lose both synchronizations, and you will have strange failover situations (probably even split-brain) This is because HA1 and HA2 are recommended to be directly connected between 2 fortigates. But if you use HA1 and HA2 even for FGSP, i thing that you will have to use switch and router devices in between. 

Knowing this, the problem is all design, not technical.

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.