Forticlient EMS geo-redundant design
Hi,
I'm officially losing after days of research and studies. The guide doesn't seem clear to me (or maybe I'm stupid enough to not get it).
I'm designing 2 DCs following Fortinet's recommended design, the 1st has 2 EMS nodes, 2DBs and 1 witness. The other DC has 1 DB and 1 witness.
what I learned so far: I need kind of load balancers, at the outside level (for requests coming from the outside) point on 2 different VIPs (DC1 and DC2), VIP of DC1 is pointing as well on both EMS servers there, DC 2 has only a single node but i'll use a VIP there as well for design purposes.
in the inside, each fortigate (of each DC) has a VIP that includes its respective EMS nodes (LAN side)
For local DNS, i'll need a load balancer here as well, so I can track the active EMS across both DCs (single FQDN, 2 IPs = 2 VIPs defined in the Fortigates; 1st VIP has both EMS nodes of DC1, and VIP of DC2 has EMS IP of DC2.
is this understanding correct? do I still need the custom hostname though (i don't see how to use it in this design)
I hope to get reactions, thanks to everyone
