FortiGate 100D HA Cluster with VRRP Routers in front
Because of a possible migration from the current datacentre to a new datacentre more nearby, I am investigation the possibilities that the new datacentre offers and the FortiGate 100D units supports.
Datacentre offers two 1 GB uplinks on copper (UTP) with VRRP for redundancy. So I took a look at the HA guide of FortiOS and see that FortiGates supports VRRP. So my though was as follow see the diagram below.
So is it possible to configure the FortiGate 100D in a FSCP cluster with in a VRRP cluster with the routers for redundancy?
What are the advantages or disadvantages?
Are there better solutions to connect the FortiGates in a redundant way?
Netwerk diagram in high level Internet
/ \ Router A Router B Routers of datacentre | | FortiGate A =========== FortiGate B Firewalls | | Swicth A ============== Switch B Stack of twoswitches
The second thing is that we want to make use of VDOMs, does this have impact on the choices for redundant connections?
I think it should be possible to configure a root / management / internet vdom that have connection to the internet and make interlinks to other VDOMs to facilitate them with internet from the root / management / internet vdom. Do I understood it right?
Are there any people who running this kind of setup and can facilitate more information then in the HA guide, like config examples, or complete step by step plan how you have implement this?
Kind Regards,
Yanick
