Cybersecurity Forum

This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.

HammKing
New Contributor

Fortigate 60C HA cluster with internet

We currently have 2 60C's in our office that is HA clustered, however, we cannot find a way to make our internet connection be able to failover like the fortinet unit.

When fortinet unit A (which is where our internet LAN is connected) is down, it will failover to unit B, but we will still have no internet connection.

3 REPLIES 3
gschmitt
Valued Contributor

Did you connect the FortiGates on a wan port (wan1 or wan2 on both) to a switch and connect the switch to the ISPs connection? ^^

HammKing

Currently no, the ISP cable is directly connected to WAN1 of unit A, but I understand where you're getting at :)

Is there any other way to achieve internet failover without using switches? We're kinda short on switches right now...

Moreover, we also have two different ISP lines attached to unit A (WAN1 and WAN2). We also configured those two in a failover setting (not load-balanced).

Thanks for the reply btw Gordon :)


In Reply to Gordon Schmitt:

Did you connect the FortiGates on a wan port (wan1 or wan2 on both) to a switch and connect the switch to the ISPs connection? ^^

gschmitt
Valued Contributor

Not that I am aware of

In a normal ha cluster it's recommended to keep the ports identical like this:

http://docs-legacy.fortinet.com/cb/html/index.html#page/FOS_Cookbook/Install_advanced/cb_install-ha.html

A cheap 100Mbit switch to connect your ISPs (actually two in your case) starts at around 10€ so if you have the money for a ha cluster don't cheap out there.

If you want to use a rackmounted switch you already got I am sure it can handle vlans to suit your needs.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.