Skip to main content
scerazy
Visitor III
October 14, 2020
Question

HA cluster A/P WAN failover

  • October 14, 2020
  • 5 replies
  • 8704 views

2x 300E in HA cluster with BGP, dedicated direct fibre for HA Heartbeat between units, each unit with WAN (active/passive provided by same ISP)

 

What do I need to configure for the WAN failover to work?

 

For now I want to tackle the WAN itself, if primary unit's active WAN link fails, how do I get all traffic routed to secondary's unit WAN ?

 

Seb

    5 replies

    lobstercreed
    New Member
    October 14, 2020

    If you have two different WAN connections (you mentioned different routing) then you need twice that number of physical connections to the firewall (put a $20 dumb switch in between).  So WAN from ISP1 (or since same ISP, let's say connections A and B) goes to wan1 and connection B/ISP2 goes to wan2 on EACH firewall.  Anything else does not work with HA cluster.  Connectivity on the firewalls should always be identical, and each WAN connection should be monitored as a condition for failover.

    scerazy
    scerazyAuthor
    Visitor III
    October 14, 2020

    I do have a VSF stack of 2 switches (not that cheap) between each Fortigate and each ISP router

    FTG1 -> switch stack - ISP router 1

    FTG2 -> switch stack - ISP router 2

     

    In normal condition FTG1 is primary, ISP router 1 is active & default

     

    I can monitor active connection, but I see no way to monitor passive connection

     

     

     

     

    lobstercreed
    New Member
    October 15, 2020

    As I said, you need to double your connections so the connectivity is the SAME on both FortiGates.  You need it to look like this instead:

     

    FTG1, wan1 -> switch stack - VLAN for ISP router 1

    FTG2, wan1 -> switch stack - VLAN for ISP router 1 FTG1, wan2 -> switch stack - VLAN for ISP router 2

    FTG2, wan2 -> switch stack - VLAN for ISP router 2

     

    You obviously don't need to double the connections going to the ISP router (probably can't) which is why I said VLAN for....  Basically you have one port on your switch to the ISP router 1 and then 2 ports to the 2 FGTs.  Same thing with ISP router 2.  6 ports on your switch, in total.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!