Inquiry on Failover Design Between Multiple Sites
Hello Expert,
I have a design question regarding our current network setup, and I’m hoping you can help clarify a few points. While this design may seem a bit unconventional, we are limited to using the switches already implemented in our design. I would like to know if what I’m proposing is feasible, and if so, how we can achieve it.
Current Setup Overview:
Site 1:
- Two FortiGate hardware devices configured in High Availability.
- The setup is functioning correctly.
Site 2 (DMZ):
- Two virtual FortiGate devices configured in HA.
- This setup is also functioning correctly.
Site 3 (LAN):
- Two virtual FortiGate devices configured in HA.
- Their HA synchronization is working fine.
Connection Between Sites:
- Site 1’s primary and backup firewalls are directly connected to Site 2’s primary and backup devices.
- Site 2’s primary and backup devices are connected to Site 3’s primary and backup devices.
Key Question:
- If the primary firewall at Site 1 goes down, I can configure link monitoring to trigger a failover to Site 2’s primary firewall. However, I am concerned about how Site 3 will be notified of this change.
- Specifically, if Site 2’s backup device becomes primary and starts sending traffic to Site 3’s backup device, will Site 3 recognize this failover?
- How Fotigate Backup device behave if it receive the traffic will it dicard?
I have attached a design diagram for your reference to help illustrate my question.

