Skip to main content
v20100
New Member
April 11, 2017
Question

Having issues setting a new pair of 200D

  • April 11, 2017
  • 9 replies
  • 8543 views

Hi

Very strange issue that kept us all day on it with no fix so far.

A few months ago, we had a couple of Checkpoint firewalls which were due to be replaced with 2 x 200D.

The 2 200D were setup in HA, we assigned them with one of our spare external IP address, plug them onto the external routers, and everything worked. We were able to migrate all the VPN tunnels from the Checkpoint to Fortigate, and then at some stage to remove the Checkpoint firewalls.

 

Now, we are trying to configure 2 new 200D to be sent to another office. Again, we configured then in HA and assigned them with an available external IP address and plugged to the external routers, but we cannot seem to make them connect to the internet properly. from the CLI, we can hardly ping 8.8.8.8 for example, but some time it works with usually at least 60% packet lost. Trace show that it goes a few hops after the first ISP router, but it gets in trouble after. Not always at the same hop.

We setup traffic from lan to internet rules, but whilst the logs in the Fortigate shows that it is OK, nothing work.

Looks like a networking issue, but cannot figure out what it could be.

Could it be an issue to have 2 sets of Fortigate on  the same switch, with the same mask? It did not see to be a problem with Checkpoint + Fortigate, but perhaps it is with 2 Fortigate?

Unless, someone else has an idea?

 

Also, does the MGNT port needs to be connected to the internet? For this new office, there are no specific Vlan for Management.

We thought we would just connect a laptop with 192.168.1.1 to configure it, and leave it empty, once the firewalls are shipped to the remote office, but we wonder if it is also one reason it cannot connect to the internet (to get the licences for example).

Tried to setup the MGNT port with an IP address from the LAN port subnet, but it was not allowed.

 

All this is very confusing. Any ideas would be greatly welcome!

 

Cheers

    9 replies

    Alby23
    New Member
    April 11, 2017

    Probably a stupid question but... the new cluster is not connected to the same network where the other cluster is installed, is that correct?

    ede_pfau
    SuperUser
    SuperUser
    April 11, 2017

    In HA mode, both cluster members use the same, virtual MAC address (L2) per port. This accelerates connectivity with external switches in case of failover.

    From the 6 bytes of that MAC, the first 3 signify Fortinet as the vendor (FTNT has several combos in use now). The 5th byte is the HA group ID in hex. The HA group-ID is a CLI-only parameter in 'conf system ha'. You should always change it from the default '0' to some cluster-specific ID.

    The last byte is port-specific. I think byte 4 is '00' always but I'm not sure about this.

     

    What happens with 2 clusters with the same group-ID on the same LAN is that packets are redirected randomly between those clusters. If, by chance, the group-name is identical as well you would have noticed that the cluster was expanded to 4 members :)

    All this is assuming that you haven't set the HA password (which is often left at default).

     

    edit: A situation where this becomes important is when you host a FGT cluster in a (external) datacenter - you can never tell if there was another FGT cluster online with the same default group-ID 0.

    Alby23
    New Member
    April 11, 2017

    This is exactly the reason of my question :)

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!