Skip to main content
deepak_verma
New Member
December 15, 2017
Question

HA setup

  • December 15, 2017
  • 2 replies
  • 5789 views

Hi  ,

 

I have 2 firewalls and trying to setup HA configuration.

 

location A --  Firewall A.

 

location B --  Firewall B .

 

As per requirement , I need to setupHA config between firewall A and Firewall B .

 

Any recommended configuration for such type of setup ..

 

Thanks ..

 

 

    2 replies

    ede_pfau
    SuperUser
    SuperUser
    December 16, 2017

    Just configure HA (a/p or a/a) following the chapter in the FortiOS Handbook. Provide a 'clear' connection to the remote location and connect the HA ports through it. I've done that before.

     

    A note: better this line doesn't use Cisco Nexus switches. The ethertype used by the Fortinet HA protocol is different from the standard ethernet, and it is used on Nexus switches internally.

    deepak_verma
    New Member
    December 17, 2017

    Hi Ede ,

     

    Thanks for your reply .

     

    So just wanted to confirm for HA port , please correct me if I am wrong here ..

     

    We just need to tag one vlan to HA ports ---  and allow it through upstream router and need to do similar at other end as well .. right ?

     

    Thanks ..

    aagrafi
    New Member
    December 18, 2017

    I think you cannot use a VLAN for HA ( at least I tried it with 5.4 and it didn't gave me an option for that).

     

    aagrafi
    New Member
    December 18, 2017

    Hi,

    You can find a lot of HA examples in the cookbook (http://cookbook.fortinet.com/?s=high+availability&cat=0). I understand that the two FGs are remote to each other. So, what type the HA links will be? Consider thet these links should be low latency, low packet loss (ideally layer 1 links).