Skip to main content
jimmyd4ng3r
New Member
December 13, 2011
Question

VRRP - how to track another interface? and how to use vrdst ?

  • December 13, 2011
  • 4 replies
  • 12180 views
Hi, I have a 2 fortigates protecting two subnets. The primary fortigate has a higher priority for both interfaces than the secondary firewall. How to I setup the VRRP so that if one of the interfaces on the primary fortigates drops, the secondary takes over the primary role for BOTH subnets? At the moment, the way I see it, if only one interface drops on the primary, it shall still be the master for the other network and thus create asymmetric routing. In the cisco world, you would track the other interface as well but there doesn' t seem to be a solution in the fortigate world that I can see. Also, can someone update me more for the vrdst option ?

    4 replies

    nyx01xnyx
    New Member
    January 22, 2015

    I'm facing the same issue

     

    jimmyd4ng3r wrote:
    Hi, I have a 2 fortigates protecting two subnets. The primary fortigate has a higher priority for both interfaces than the secondary firewall. How to I setup the VRRP so that if one of the interfaces on the primary fortigates drops, the secondary takes over the primary role for BOTH subnets? At the moment, the way I see it, if only one interface drops on the primary, it shall still be the master for the other network and thus create asymmetric routing. In the cisco world, you would track the other interface as well but there doesn' t seem to be a solution in the fortigate world that I can see. Also, can someone update me more for the vrdst option ?

    berimbau
    New Member
    February 18, 2015

    Hi,

     

    Depending on which version is your Fortigate.

    But on 5.2 there is a new parameter "vrgrp" , with this you can put all your vrrp interface on the same group, this way the state is tracked and all the vrrp interface on the same group will fail back.

     

    Regards

    emnoc
    New Member
    February 18, 2015

    FWIW: The cisco like track is not available in a FortiOS, so you have no means to do this.

     

     

    dpsguard
    New Member
    December 26, 2017

    Sorry for posting in the old thread.

     

    1. Is there a way to force master unit to become backup if attached ISP circuit on master goes down (interface monitoring or virtual wan link, health check)? In my case, I will be using two ISPs on each FGT, so SD-WAN interface and thus looking for failure of both ISPs at the same time. These two ISPs will be two circuits from same ISP, just one high speed and another low speed. The second unit will have cellular Internet (to start with, later on, I will connect high speed circuit to both firewalls).

    2. Is vrdst IP of something on the internet (like Google DNS) be used to track absence of route thru the ISP to trigger making master as backup? The CLI guide is confusing as it states vrdst IP to be next hop address.

    3. Does a master unit losing the VRRP advertisement response, remain master or it decreases its priority to become slave? Else both units can become master at the same time?

    4. Hopefully SD-WAN and VRRP can be used simultaneously.

     

     Thanks

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!