Skip to main content
DirkDuesentrieb
New Member
May 4, 2022
Question

server load balancing finally works since FOS 6.4

  • May 4, 2022
  • 17 replies
  • 8954 views

Hi,
the Fortigate has the vip type "server-load-balance" for a while and some features eg https offloading and cookie persitence looked promising, but there was a bug in the cookie handling that spoiled it all.

Since FOS 6.4 this is fixed and we use this simple slb for a while without issues. So if you think about replacing a fully blown ADC (F5,A10,FortiADC) with this feature, the following might be interesting for you.

 

Features

  • Supported Protocols: https, generic ssl, http, tcp, udp and generic ip
  • https offloading with optional crypto tuning
  • http redirect to https
  • HSTS and HPKP
  • secure cookies
  • simple http header manipulation (via web-proxy profile)
  • usable health checks
  • Automation through FGs standard REST API

Limitations

  • SNAT is limited to FGs interface IP 
  • Event logging can't show VIP or real server. Works with FAZ though
  • LB Monitor Dashboard shows only (static) configured state and not the health status
  • max 16 real server on 1HU devices
  • health checks might be redundant if real servers are reused in multiple VIPs

Missing

Advanced ADC features like

  • Content rewriting
  • Scripting (irules/aflex)
  • Caching
  • SNI

 

I like this feature because we didn't need a different dedicated box with individual handling, training, contracts and all. My hope: more admins use it and someone at FTN finds time to improve at least the dashboard limitation. Why did they make a dashboard that is static???

 

Regards,

Dirk

17 replies

Contributor III
May 10, 2022
Hello @DirkDuesentrieb,
 
Thank you for using the Community Forum. We appreciate the information you have shared in the forum, although we think it is better suited to be an article instead so that everyone can make use of this useful information. We will work on this to create an article. We thank you for this great information.
 
Thanks,
DirkDuesentrieb
New Member
May 12, 2022

Hello @Anonymous ,

 

yes I'll need help - I don't know where/how to create an article.

 

Regards,

Dirk

DirkDuesentrieb
New Member
May 17, 2022

Hello all,

please note that at time of writing this, http-multiplex must be unset! Otherwise some clients will have connectivity issues in case of a realserver going down, because rebalancing of sessions with existing cookies will not work.

 

Regards,

Dirk

Debbie_FTNT
Staff & Editor
Staff & Editor
May 17, 2022

Hey Dirk,

at the moment, (KB) articles can only be created by Staff, not other community members.

I'm not sure if this will change, but I will reach out to the dedicated community team regarding your thread to see what can be done :).

Again, thanks for compiling the information in such an easily accessible format!

jintrah_FTNT
Staff
Staff
May 18, 2022

Hi Dirk,

 

The SNAT is not limited to interface IP, we can have IP-Pools for SNAT.

 

jintrah_FTNT_0-1652861648710.png

 

best regards,

Jin

jintrah_FTNT
Staff
Staff
May 18, 2022

The realtime health monitor is available in the dashboard with healthcheck status. A sample below,

 

jintrah_FTNT_1-1652862126927.png

 

best regards,

Jin

 

jintrah_FTNT
Staff
Staff
May 18, 2022

Dear Dirk,

 

You mentioned "Event logging can't show VIP or real server. Works with FAZ though"

 

But I think whatever generated on FortiGate is only viewable in FAZ. Is there any sample log you can provide which you didnt see on FortiGate but on FAZ(RAW log please and no csv, please).

 

Best regards,

Jin

DirkDuesentrieb
New Member
May 18, 2022

Hello @jintrah_FTNT ,

 

I did a quick retest and you are right it works (now), what was a bit surprising to me be because I had lots of sniffer dumps from my previous tests that showed a different behavior. The important change was unsetting http-multiplexing! Because it's turned off now, SNAT works. Bug or Feature? At least something to add to the article. Can you correct it?

 

Regards,

Dirk

jintrah_FTNT
Staff
Staff
May 18, 2022

Hi Dirk,

 

You should be able to get it working with http-multiplexing or without, the snapshot I shared earlier was taken when the multiplexing setting was enabled.

 

Best regards,

Jin

DirkDuesentrieb
New Member
May 18, 2022

Hi @jintrah_FTNT ,

 

my box has FOS6.4.9. If I turn on http-multiplex for a VIP, the SNAT-Pool is ignored and the interface VIP is used to connect to the real server. 
If I turn it off (and wait for sessions to time out) SNAT works again.

Just ran a tcpdump to confirm, because the traffic log claims that it it uses the pool IP - but it doesn't.

 

Regards,
Dirk

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!