Question
MAC address changes on default gateway -> sessions not updated
we have the following configuration at a customer: the default gateway of the fortigate is a checkpoint cluster. when a failover occurs on the checkpoint cluster, the fortigate seems to receive the change. I can see that the ARP table has been updated and the IP address of the default gateway points to the new MAC address of the other checkpoint cluster member. new sessions are working properly. but existing sessions don' t work anymore. it seems they are routed to the MAC address of the failed cluster member. I have to kill the session on the fortigate or waiting for the session timeout to occur. is this behaviour by design? shouldn' t the Fortigate update all the sessions which point to the wrong MAC address?
