Skip to main content
Kabuto
New Member
March 8, 2018
Question

VRRP with interface tracking between 2 FG200E in standalone mode

  • March 8, 2018
  • 9 replies
  • 10239 views

We are looking to configure VRRP between 2 FG200E devices in standalone with the interface tracking options.

So that when for example the public facing interface goes down and the other FG200E the inside interface will follow.

We tried already with vrgrp and vrdst to make it work but so far its not working.  (fw are configured using serveral VDOMs running 5.6.2)

 

First question, is this even possible on the 200Es? If yes how should it be configured so that both interface outside/inside will become active on the same device when either one of the 2 fails on the active device.

 

Thanks for having a look at it!

    9 replies

    Toshi_Esumi
    SuperUser
    SuperUser
    March 8, 2018

    As long as those are individual interface, like port1, port2,..., VRRP should work throughout FG models. What do you get with "get router info vrrp" on both sides?

     

     

    Kabuto
    KabutoAuthor
    New Member
    March 9, 2018

    Individual interfaces only? we have a Portchannel configured connecting to a stacked switch using subinterfaces for inside and outside subnets, using layer 2 seperation on the stacked switch.

     

    So it could be thats not working in combination with PortChannels.

    Interfaces below are subinterfaces.

     

    Output of get router info vrrp:

    Interface: Extranet-Inside, primary IP address: 10.10.10.19 UseVMAC: 1, SoftSW: 0, BrPortIdx: 0, PromiscCount: 1 HA mode: master (2:2) VRID: 2 vrip: 10.10.10.18, priority: 255 (255,10), state: MASTER adv_interval: 1, preempt: 1, start_time: 3 vrmac: 00:00:5e:00:01:02 vrdst: 10.10.10.21 vrgrp: 1 Interface: Extranet-Outside, primary IP address: 74.159.41.2 UseVMAC: 1, SoftSW: 0, BrPortIdx: 0, PromiscCount: 1 HA mode: master (2:2) VRID: 1 vrip: 74.159.41.1, priority: 255 (255,10), state: MASTER adv_interval: 1, preempt: 1, start_time: 3 vrmac: 00:00:5e:00:01:01 vrdst: 8.8.8.8 vrgrp: 1

     

    Other fw1

    Interface: Ext-Inside-Po2, primary IP address: 10.10.10.20 UseVMAC: 1, SoftSW: 0, BrPortIdx: 0, PromiscCount: 0 HA mode: master (1:2) VRID: 2 vrip: 10.149.148.18, priority: 75 (75,0), state: BACKUP adv_interval: 1, preempt: 1, start_time: 3 vrmac: 00:00:5e:00:01:02 vrdst: 10.10.10.21 vrgrp: 1 Interface: Extr-Out-Po2, primary IP address: 74.159.41.3 UseVMAC: 1, SoftSW: 0, BrPortIdx: 0, PromiscCount: 0 HA mode: master (1:2) VRID: 1 vrip: 74.159.41.1, priority: 75 (75,0), state: BACKUP adv_interval: 1, preempt: 1, start_time: 3 vrmac: 00:00:5e:00:01:01 vrdst: vrgrp: 1

     

    Thanks for having a look at it!

     

    Toshi_Esumi
    SuperUser
    SuperUser
    March 9, 2018

    I haven't tried portchannel/LAG myself but it looks working based on the output. The first one is MASTER w/ priority 255, then the second one is BACKUP w/ priority 75. So traffic doesn't come in and flow through the first FG200E?

    Toshi_Esumi
    SuperUser
    SuperUser
    March 16, 2018

    Whatever works for you that would be a solution for you. We have multiple HA clusters with multi-vdom environment. It works quite well. VRRP standard's original scope was to protect operation from an interface failure. It's not designed to protect from equipment failure. Just keep it in mind.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.