Cybersecurity Forum

This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.

hiendam
New Contributor II

HA additional port

​​Hello guys,

I am a beginner on Fortigate. I have a question about the HA port.
Is it possible to configure two HA ports on each Forti 200E to create a Active/Passive cluster? I saw only one HA port on the Datasheet.
Thank you very much.

Regards.
8 REPLIES 8
faridulalam_FTNT

Hi hien,
Yes, you can configure 1/2/3... HA ports in A/A or A/P cluster.


------------------------------
Faridul
------------------------------
[FirstName] [JobTitle]
hiendam

Hi Faridul,

Thank you for your quick response.

So if I use port1, port2 for HA connections, this HA port will be unused. Am I right?

Is this HA port dedicated only for HA? Can I use it for other purpose?​
faridulalam_FTNT

Hi hien,
Depending on Firewall model, there might be 1/2 dedicated HA port(s), but you can use any physical port as HA port(s).
But, never use any logical port in HA, like: Software Switch port(s), Hardware Switch port(s), Redundant/Aggregation port(s)...etc.

In FortiGate:
1. Any ports can be data ports.
2. Any HA ports can be data ports.
3. You can convert any dedicated management (OOB > Out-of-Band Management) ports to data ports.
4. Yes, in FGT - You can do the combination of dedicated HA port and regular data port as HA ports.




------------------------------
Faridul
------------------------------
[FirstName] [JobTitle]
ShadYaka
New Contributor

Dear Hien,

The answer to your question is YES!

You can assign another port as HA to the dedicated HA port. With this, you will leverage on configuration  and session synchronization of the cluster
hiendam
New Contributor II

Hi Shadrack,

In order to give the max port occupation, may I configure like this:
HA port and port1 (for example) for the cluster?​
faridulalam_FTNT

Yes, in FGT - You can do the combination of dedicated HA port and regular data port as HA ports

------------------------------
Faridul
------------------------------
[FirstName] [JobTitle]
hiendam

Thank you all of you guys.

I got it. So Fortigate is very flexible and simple about configuration.​
ShadYaka

Yes Sure!

Go ahead and select  the dedicated HA port and port1 under Heatbeat interfaces for your High Availability Setup.