Cybersecurity Forum

This forum is for all security enthusiasts to discuss Fortinet's latest & evolving technologies and to connect & network with peers in the cybersecurity hemisphere. Share and learn on a broad range of topics like best practices, use cases, integrations and more. For support specific questions/resources, please visit the Support Forum or the Knowledge Base.

DeepKuma2
Contributor

Load Balancing with Active Passive

Is it possible to load balancing with Active-Passive HA mode? Yesterday I have attended an training of Fortigate and trainer says it is possible but FortiGate documents say no.

Can anyone guide me, I am in confuse right now. 

 

 

Regards,

Deepak Kumar

Deepak Kumar First Option General Trading LLC Dubai
Deepak Kumar First Option General Trading LLC Dubai
1 Solution
rmoussa

You can follow this link :

http://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-whats-new-54/Top_VirtualWANLink.htm

Choose source-destination ip based as algorithm . Thats the most effective if you have identical wan connections.

For each wan switch connect one cable to FG1 and another to FG2.

Rony Moussa

NSE Certified : Level 8

Rony Moussa
Fortinet NSE Certified: Level 8

View solution in original post

Rony MoussaFortinet NSE Certified: Level 8
12 REPLIES 12
DeepKuma2

Hi, 

Thanks for sharing knowledge. I am not sure it will work because FortiGate clearly mentions

 

"An active‑passive cluster consists of a primary unit that processes communication sessions, and one or more subordinate units. The subordinate units are connected to the network and to the primary unit but do not process communication sessions. Instead, the subordinate units run in a standby state. In this standby state, the configuration of the subordinate units is synchronized with the configuration of the primary unit and the subordinate units monitor the status of the primary unit."

http://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-high-availability-52/HA_FGCP_ap_aa.htm

 

 

 

Regards,

Deepak Kumar

Deepak Kumar First Option General Trading LLC Dubai
Deepak Kumar First Option General Trading LLC Dubai
rmoussa

Dear,

We are running these scenarios for hundreds of customer with thousands of users and it is supported by Fortinet.

One of the customer we are using load balancing for has around 28000 clients connected and we are using 2 WAN Links of 800 Mbps each.

And Fortigates are installed in HA Active-Passive Mode

Rony Moussa

NSE Certified : Level 8

Rony Moussa
Fortinet NSE Certified: Level 8
Rony MoussaFortinet NSE Certified: Level 8
MichaelBazy

If this is about load-balancing among several internet links (Wan Link Load Balancing in 5.2/5.4, SD-Wan in 5.6), it has nothing to do with clusters :

a standalone Fortigate can do it

a A-P cluster can do it

a A-A cluster can do it

However, in the training, load-balancing in A-A clusters is about load-balancing between several FortiGates. That way you can use more actively the CPU of another FortiGate in the cluster (which justifies the ability to use up to 4 units in a cluster).

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.