Cybersecurity Forum

This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.

DeepKuma2
Contributor

Load Balancing with Active Passive

Is it possible to load balancing with Active-Passive HA mode? Yesterday I have attended an training of Fortigate and trainer says it is possible but FortiGate documents say no.

Can anyone guide me, I am in confuse right now. 

 

 

Regards,

Deepak Kumar

Deepak Kumar First Option General Trading LLC Dubai
Deepak Kumar First Option General Trading LLC Dubai
1 Solution
rmoussa

You can follow this link :

http://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-whats-new-54/Top_VirtualWANLink.htm

Choose source-destination ip based as algorithm . Thats the most effective if you have identical wan connections.

For each wan switch connect one cable to FG1 and another to FG2.

Rony Moussa

NSE Certified : Level 8

Rony Moussa
Fortinet NSE Certified: Level 8

View solution in original post

Rony MoussaFortinet NSE Certified: Level 8
12 REPLIES 12
AnanNara
New Contributor

I have multiple FG-300D and FG-500D spread across the locations and the HA are configured in A-P Please refer the following document as reference

http://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-high-availability-52/HA_FGCP_ap_aa.htm

[FirstName][JobTitle]
[FirstName][JobTitle]
DeepKuma2

Hi,

Thanks for the reply but I am not looking any reference documents for the configuration. I am looking the solution that is there any hidden command from FortiGate to make load balancing on A-P mode. Which may Fortigate is not sharing in his documents and want to share only on NSE8 certified engineer.  

 

Regards,

Deepak Kumar

Deepak Kumar First Option General Trading LLC Dubai
Deepak Kumar First Option General Trading LLC Dubai
Vilela
New Contributor

I think this is possible if you are enabling virtual VDOM.
Use Virtual clustering and HA override

"Usually you would enable virtual cluster 2 and expect one cluster unit to be the primary unit for virtual cluster 1 and the other cluster unit to be the primary unit for virtual cluster 2. For this distribution to occur override must be enabled for both virtual clusters. Otherwise you will need to restart the cluster to force it to renegotiate."

 

https://www.fortinetguru.com/2016/09/virtual-clusters/

 

 

Vilela

Brazil-Brasilia

Leandro Vilela Brasil
Leandro Vilela Brasil
DeepKuma2

What do you think? Is it load balancing or resources load balancing?

Regards,

Deepak Kumar

Deepak Kumar First Option General Trading LLC Dubai
Deepak Kumar First Option General Trading LLC Dubai
Vilela

Resource Load balance

Regards

Vilela

Brazil-Brasilia

Leandro Vilela Brasil
Leandro Vilela Brasil
DeepKuma2

Hi,

But I am talking about load balancing.

Regards,

Deepak Kumar

Deepak Kumar First Option General Trading LLC Dubai
Deepak Kumar First Option General Trading LLC Dubai
rmoussa

If you are talking about Wan Link Load Balancing, yes it is possible

Rony Moussa

NSE Certified : Level 8

Rony Moussa
Fortinet NSE Certified: Level 8
Rony MoussaFortinet NSE Certified: Level 8
DeepKuma2

Hi,

Yes, I am talking about wan load balancing. Please guide for same, how can I configure the same?

Regards,

Deepak Kumar

Deepak Kumar First Option General Trading LLC Dubai
Deepak Kumar First Option General Trading LLC Dubai
rmoussa

You can follow this link :

http://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-whats-new-54/Top_VirtualWANLink.htm

Choose source-destination ip based as algorithm . Thats the most effective if you have identical wan connections.

For each wan switch connect one cable to FG1 and another to FG2.

Rony Moussa

NSE Certified : Level 8

Rony Moussa
Fortinet NSE Certified: Level 8
Rony MoussaFortinet NSE Certified: Level 8