Skip to main content
MustphaBassim
New Member
April 23, 2022
Question

HA issue

  • April 23, 2022
  • 1 reply
  • 1267 views

Hello Dears

 

I have two firepower devices (HA active/standby) connected to two fortigate firewalls (HA active/standby) when both of the fortigate firewalls are working the HA status become faild while when i stop one of the fortigate devices the HA status become fine anyone have idea about this issue ? take in mind the connection is :

 

FG1-Port3<-->FP1-Port3

FG1-Port4<-->FP2-port4

FG2-Port3<-->FP1-Port4

FG2-Port4<-->FP2-Port3

1 reply

Toshi_Esumi
SuperUser
SuperUser
April 24, 2022

That generally wouldn't work for both sides. Cisco doc below indicates FTD's HA seems to work quite similar to FGT's HA. You need to have at least one switch inbetween so that FG1/FG2 port3s and FP1/FP2 port3s are on the same broadcast domain, and same goes with port4s.

 

https://www.cisco.com/c/en/us/td/docs/security/firepower/650/configuration/guide/fpmc-config-guide-v65/high_availability_for_firepower_threat_defense.html

 

Toshi

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!