Skip to main content
vishal
Visitor III
June 9, 2021
Question

Hsrp behaviour in High availibility

  • June 9, 2021
  • 5 replies
  • 7960 views

Hello All,

 

I have 2 FGT in A-P Mode running in my organisation connected to two MPLS router (interconnected with trunk link) as outside and two core switches (in Stack) as inside zone. Please refer the attached diagram.

 

Basically i want to achieve redundancy of my ospf routes from fortigate means if my Acitve FGT port 34 connected with Router 1 goes down then then firewall switchover and all traffic should divert to port 36 of Standby FGT .

 

Please guide me is this possible with my current diagram ?. If no then what are the changes i need to do in current diagram ? If yes then what are the changes i need to do configure on FGT

 

Please help

 

    5 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    June 9, 2021

    The base concept of A-P is both FGT config needs to be identical. Then you can't configure two ports in the same subnet between 34 and 36. Besides, without an L2 switch between the FGTs and routes, if Router1 dies while FGT1 is active the FGT1 can't get to Router2. So you need to place a switch(or cluster of switches) like LAN side.

     

    Then LAN side, for the same reason above, you can't form one LAG/LACP split to A and P device. You have to have two LAG ports on both FGTs. Then you can split two cables from each FGT to two switches so that you have switch redundancy. 

     

    vishal
    vishalAuthor
    Visitor III
    June 10, 2021
    Hello Toshi, Thanks for your reply. For routes reachability if I remove port 36 from FGT 2 and use only port34 as we are using for FGT 1 . Then would I achieve failover of routes if any link goes down without placing any switch in between routers and firewall ? Also for lan side if I remove lacp from FGT and switch side both and use single port from each FGT to each switch running in stack then I think so it would not be a problem ?. Please share your views also if I'm wrong
    Toshi_Esumi
    SuperUser
    SuperUser
    June 10, 2021

    If no switch on WAN side, the FGT1 can't reach RT2. Heartbeat connections are just for communication between FGTs, not for user traffic. I would use the same switch cluster on the LAN side for WAN then separate them with VLANs. On LAN side, you want to keep LACP with two port from both FGT (total 4 cables). Then split portA to sw1 and portB to sw2 for each FGT.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!