Skip to main content
SaeedAbdelHalim
New Member
December 8, 2024
Question

I have 2 fortigate with HA A-P need to connect with 2 Cisco Layer 3 switch

  • December 8, 2024
  • 9 replies
  • 2286 views

core switch working as layer 3 routing per vlans 

and the two fortigate working as HA A-P 

i need two know how the connection works 

the design also , if there more the idea please need to know all possible solutions and if there any topology diagram the clarify the solution 

9 replies

sjoshi
Staff
Staff
December 8, 2024
Thanks, Salon
SaeedAbdelHalim
New Member
December 9, 2024

it`s not nexus , it`s CAT switch , and  it`s layer 3 all the routing vlan done one it 

 

DPadula
Staff & Editor
Staff & Editor
December 8, 2024

Hi Saeed.
Are those 2 cisco switches connected to each other as a stack or independents?
If the Cisco switches are setup as stack, you can use MCLAG instead

Regards

DPadula

 

 

SaeedAbdelHalim
New Member
December 9, 2024

no it`s not stacked

Toshi_Esumi
SuperUser
SuperUser
December 9, 2024

If the switches are stacked, you just need to have two connections (each could be LAG/Port-channel for switch side redundancy) to both unit, then span the same VLANs to both. Remember, in A-P HA only one unit is active. Then it would simply fail-over from one unit to another when an HA event happens.

Toshi

SaeedAbdelHalim
New Member
December 9, 2024

dear i all vlan on core switch not fortigate 

Toshi_Esumi
SuperUser
SuperUser
December 9, 2024

If they're not stacked, and no VLANs are coming to the FGTs, it's simple.
If those two switches are cascaded, you need to connect from the root switch to both FGTs on the same broadcast domain. If those are "parallel" each need to connect both FGTs with separate subnets because those switches are independent L3 routers.
It's up to L3 design on the L2/L3 router/switch side.

Toshi

SaeedAbdelHalim
New Member
December 9, 2024

cloud you please provide my with design 

Toshi_Esumi
SuperUser
SuperUser
December 9, 2024

What I implied with my previous message was without knowing your L3 design between those two L3 switch/routers with the FGT(in HA), and some key L3 topology on the Cisco side, it's impossible to design it.

Toshi

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!