VRRP configuration on cluster
Hi
I'm working on a new design and I need to know if this is possible or not.
Currently, we have 2 server rooms in separate buildings. In each location we have a core switch with a L3 routed connection between them. We have stretched vlans between the rooms, using VRRP on the core switches. This allows us to vmotion VM from roomA to roomB, without changing IP details. Each of the server vlans are using the VRRP ID from the switches as their gateway.
We also have a Fortgate HA cluster in A-P mode. The active member is in roomA with the passive member in roomB.
What I want to do is move the server vlans behind the firewall. Is this just a simple case of moving the VRRP configuration to the Fortigate cluster? How would this work, if there are servers on the same subnet/vlan in each room but there is a passive fortigate cluster member in the room? Or should the cluster be changed from A-P to A-A mode? I'm just trying to work out how the traffic would flow.
Thanks
Roy