Migrating HA setup from 501E to 100F
Hi everyone!
We current have a HA Setup for FG 501E.
The physical HA ports are interconnected via switch in between. The switch ports are on the same vlan.
The physical HA port also has an IP Address set with it. Assume 1.1.1.1
As I have checked, 100F does not have this single HA port same as 501E. It uses HA1 and HA2.
Now I am thinking, to replicate our current setup to this new 100F firewall pair, can I use the same switch interconnectivity for the HA1 and assign an IP Address to the HA1 interface? Can i also leave the HA2 interfaces directly connected (w/out switch) to each firewall?
The reason why I want to replicate this is because I have found out that:
- The communications between Fortiguard servers and our existing 501E Firewalls are using a security policy; in which the HA IP address (1.1.1.1) was being referenced.
Regards,
Renz


