FortiGate 601F v7.2.8 HA Pair with VDOMs and Virtual Clustering
We recently upgraded from a standalone FortiGate 1500D running FortiOS 7.2.8 to a pair of Fortigate 601Fs running the save version of FortiOS as an Active-Passive HA pair. Our deployment consists of 10 total VDOMs and 8 10G physical interfaces. There are also 2 copper HA links and 1 copper management link per FortiGate.
For this deployment's configuration, we pulled a config from the current FortiGate 1500D, passed it through FortiConverter, and loaded the resulting configuration onto the new FortiGate 601F's without issue. All references and settings were identical to the previous FortiGate.
Each physical interface contains either the inside, dmz, or public vlans for multiple clients that we service. The physical interfaces themselves have no IP assigned to them. Rather, each physical interface holds multiple disjoint subnets corresponding to a client's network.
Although the physical interfaces are grouped by inside, dmz, public, the VDOMs are grouped according to client. For Example, we have a VDOM named district that includes one vlan each from physical interfaces x8,x5, and x4 and another VDOM named Support that includes three vlans from x8, two vlans from x7, three vlans from x5, 2 vlans from x2, and 2 vlans from x1. This means that each physical interface has vlans that are a part of 2 or more separate VDOMs (2 in this example, but some physical interfaces contain vlans spread among as many as 5 VDOMs).
For this deployment, we were hoping to make use of the virtual clustering feature available when deploying 2+ FortiGates in an HA pair. This feature seemed beneficial as it allows the bandwidth per VDOM to be distributed between both FortiGates while maintaining the Active-Passive topology.
Are there any known issues with the same physical interface being a part of multiple VDOMS (and ultimately multiple virtual clusters) when the physical interfaces are not addressed but the vlans within them are?
An initial review of available references resulted in very little explanation for this scenario. I'm hoping somebody has either previously deployed this topology or has a more firm understanding of how HA virtual clustering functions on a per-vlan rather than a per-physical interface basis.
It is important to note that although each physical interface has vlans in at least 2 different vdoms, each vdom contains at least one unique public IP subnet and is a fully functional self contained network. My biggest question is if virtual clustering allows the active-passive topology on a per-vlan basis?
Our goal is to deploy 2 virtual clusters, each as the primary for 5 VDOMs. However, in any group of 5 VDOMs, there will be at least one vlan belonging to each physical interface. This means that each virtual cluster will be primary for some vlans on a physical interface, and passive for other vlans on the same interface.
Thanks for your help!
FortiGate #VirtualClusters #HA #VDOMs
