Skip to main content
Ganaa
New Member
March 20, 2026
Solved

OSPF between Clusters

  • March 20, 2026
  • 2 replies
  • 240 views

Hi everyone,

I have a design question regarding connectivity between two FortiGate HA clusters.

Currently, I have two FortiGate clusters configured in Active-Passive (A-P) mode. Instead of directly connecting the clusters, both are connected through a Cisco Core switch (Layer 2) using aggregated interfaces (port-channel). Under these aggregate interfaces, multiple VLAN subinterfaces are configured.

  • Only one cluster (FG1101E) has a public IP address and is responsible for Internet access.

  • The other cluster (FG100E) does not have a public IP and must route Internet-bound traffic through the FG1101E cluster.

  • Additionally, some VLANs on both clusters need to communicate with each other (inter-VLAN/inter-cluster traffic).

Given this setup, I am considering two design approaches:

  1. Assigning IP addresses from the same subnet on the aggregate interfaces of both clusters and using static routes.

  2. Running OSPF between the two clusters for dynamic routing.

My main goal is to simplify routing, reduce the number of static routes, and ensure stable operation, especially during HA failover scenarios.

Which approach would you recommend in this case, and why? Are there any best practices or potential pitfalls I should be aware of?

Best answer by Toshi_Esumi

Based on your description, HA wouldn't impact anything for routing between two routers (clusters). Only one side is active and if HA flips over, the other side takes it over since those VLANs are spanned to both sides by the switch.

So it's basically just two routers. If you have a routing protocol like OSPF between them, you  wouldn't need any static routes other than possible static route(s) on the internet router(cluster). But if all of those VLAN's L3 interfaces are on either router (cluster), only routes you need is for all subnets on the other router (cluster). I wouldn't see much difficulties or complication even if you do everything with static routes. Unless the number of VLAN/subnets on both side are like more than a couple of dozens. 

Another factor is if those subnets would change or get added/remoded often, a routing protocol of course would help without needing any static routes additions/deletions/changes because it would be automatic.

Toshi

2 replies

Toshi_Esumi
SuperUser
SuperUser
March 20, 2026

Based on your description, HA wouldn't impact anything for routing between two routers (clusters). Only one side is active and if HA flips over, the other side takes it over since those VLANs are spanned to both sides by the switch.

So it's basically just two routers. If you have a routing protocol like OSPF between them, you  wouldn't need any static routes other than possible static route(s) on the internet router(cluster). But if all of those VLAN's L3 interfaces are on either router (cluster), only routes you need is for all subnets on the other router (cluster). I wouldn't see much difficulties or complication even if you do everything with static routes. Unless the number of VLAN/subnets on both side are like more than a couple of dozens. 

Another factor is if those subnets would change or get added/remoded often, a routing protocol of course would help without needing any static routes additions/deletions/changes because it would be automatic.

Toshi

Toshi_Esumi
SuperUser
SuperUser
March 20, 2026

Oh, by the way, the internal router/cluster side just needs a default route toward the internet router/cluster over the interconnect VLAN, because 0/0 would include all those VLAN subnets on the other side in addition to all internet destinations.
The internet router/cluster side need to have 0/0 routes toward the internet circuits/interfaces, while all other internal router subnets/routes toward the interconnect VLAN. 

Toshi

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!