This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.
Is it possible to load balancing with Active-Passive HA mode? Yesterday I have attended an training of Fortigate and trainer says it is possible but FortiGate documents say no.
Can anyone guide me, I am in confuse right now.
Regards,
Deepak Kumar
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
You can follow this link :
http://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-whats-new-54/Top_VirtualWANLink.htm
Choose source-destination ip based as algorithm . Thats the most effective if you have identical wan connections.
For each wan switch connect one cable to FG1 and another to FG2.
Rony Moussa
NSE Certified : Level 8
Hi,
Thanks for sharing knowledge. I am not sure it will work because FortiGate clearly mentions
"An active‑passive cluster consists of a primary unit that processes communication sessions, and one or more subordinate units. The subordinate units are connected to the network and to the primary unit but do not process communication sessions. Instead, the subordinate units run in a standby state. In this standby state, the configuration of the subordinate units is synchronized with the configuration of the primary unit and the subordinate units monitor the status of the primary unit."
http://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-high-availability-52/HA_FGCP_ap_aa.htm
Regards,
Deepak Kumar
Dear,
We are running these scenarios for hundreds of customer with thousands of users and it is supported by Fortinet.
One of the customer we are using load balancing for has around 28000 clients connected and we are using 2 WAN Links of 800 Mbps each.
And Fortigates are installed in HA Active-Passive Mode
Rony Moussa
NSE Certified : Level 8
If this is about load-balancing among several internet links (Wan Link Load Balancing in 5.2/5.4, SD-Wan in 5.6), it has nothing to do with clusters :
a standalone Fortigate can do it
a A-P cluster can do it
a A-A cluster can do it
However, in the training, load-balancing in A-A clusters is about load-balancing between several FortiGates. That way you can use more actively the CPU of another FortiGate in the cluster (which justifies the ability to use up to 4 units in a cluster).
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.