This article describes how to configure the FortiAnalyzer HA instance in the Google Cloud Platform (GCP).
FortiAnalyzer-VM for GCP.
Important note:
FortiAnalyer HA instances |
Region |
faz-a-vm |
asia-southeast1-a |
faz-b-vm |
asia-southeast1-a |
faz-c-vm |
asia-southeast1-b |
Google Cloud Platform (GCP):
Make sure all FortiAnalyzer-VM instances have set Cloud API -> Compute Engine access to Read Write
GPC Portal -> Compute Engine -> VM instances -> Select the VM instance -> Details -> Edit -> Cloud API access -> Compute Engine -> Read Write -> Save.
Note:
Cloud API access can only be changed when the VM instance is stopped/shutdown.
GCP Firewall Policy |
Description |
protocol 112 |
For HA keepalive / VRRP |
tcp 514 |
For initial log sync |
tcp 5199 |
For Configuration sync |
GPC Portal -> VPC network -> Select the network -> Firewall -> Edit/Add Firewall rule -> Save/Create.
Note:
Ensure the firewall policy target is set correctly.
Note:
If External IP is used as Virtual IP like in this example, the network tier must be Premium.
FortiAnalyzer:
Primary and Secondary VM:
Test failover:
FAZ-A # diag ha failover
Related article:
Technical Tip: FortiAnalyzer HA Configuration and Troubleshooting
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.