Skip to main content
magarm
New Member
September 21, 2025
Solved

Load-balancer mode deployment failover

  • September 21, 2025
  • 4 replies
  • 575 views

In Load-balancer mode deployment, what happens if primary fac goes down? for an example , I have cluster(A-P) as a primary at HQ and load-balancer at two different geo location.

what happens if my primary HQ is down? can load-balancer take over authentication function.

if so which will be active.

 

 

Best answer by AEK

There is no automated failover between them, and devices utilizing the FortiAuthenticators will need to switch to a different IP address to address a different node, as if switching to a completely independent device.

Ref:  https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-How-to-configure-FortiAuthenticator-load-balancing/ta-p/190416

 

E.g.: if you are using RADIUS authentication, on each device you configure the first FAC as primary and the second as secondary.

You can also achieve the fail-over via a separate load-balancer (I mean LB like FortiADC). In this case the devices send the authentication request to the LB and the LB knows which FAC is up and which one is down.

4 replies

AEK
SuperUser
AEKAnswer
SuperUser
September 21, 2025

There is no automated failover between them, and devices utilizing the FortiAuthenticators will need to switch to a different IP address to address a different node, as if switching to a completely independent device.

Ref:  https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-How-to-configure-FortiAuthenticator-load-balancing/ta-p/190416

 

E.g.: if you are using RADIUS authentication, on each device you configure the first FAC as primary and the second as secondary.

You can also achieve the fail-over via a separate load-balancer (I mean LB like FortiADC). In this case the devices send the authentication request to the LB and the LB knows which FAC is up and which one is down.

AEK
magarm
magarmAuthor
New Member
September 25, 2025

Can the load-balancer fortiauthenticator at Branch perform authentication (MFA, SSO) of local application. or it forwards the traffic to primary cluster?

AEK
SuperUser
SuperUser
September 25, 2025

Yes the FAC on branch is actually intended to perform authentications for branch applications.

And no it doesn't forward the authentication traffic to the primary.

AEK
Staff
February 10, 2026

hi @magarm be aware of the license part:

https://docs.fortinet.com/document/fortiauthenticator/8.0.0/administration-guide/122076/high-availability

FortiAuthenticator VMs used in a HA cluster each require a license. Each license is tied to a specific IP address. In an HA cluster, all interface IP addresses are the same on the units, expect for the HA interface.

Request each license backed on either the unique IP address of the unit's HA interface or the IP address of a non-HA interface which is the same on both units.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!