FortiGate Azure ExpressRoute Setup
- August 25, 2021
- 5 replies
- 12825 views
Curious for a bit of input on how to make this work, as this is our first FortiGate deployment. Due to limitations in ability to use redundant static routes on Meraki, we are looking to set the FortiGates up in an Active-Passive cluster so we can create a VIP and have a single IP to create a static route to on the Meraki MX firewalls (our assumption is that the FortiGates have to be in a cluster to create a VIP). See setup A (attached) The problem is that my understanding is that once clustered, the FortiGate configs have to be identical, and that's an issue because the secondary ExpressRoute link from Azure is on a different /30 space and needs a different IP.
Also looked into configuring WAN 1 and WAN 2 in SD-WAN group with both FortiGates connected to both ExpressRoute circuits, but similarly this is not feasible because both ExpressRoute links are tagged with same VLAN (1003) so we cannot set the VLAN interface for the same VLAN to be both .1 and .5 for the WAN 1 and WAN 2 interfaces (if that makes sense).
Really appreciate any thoughts anyone may have. Also open to suggestions if we are approaching this from the wrong angle altogether.
