Created on 09-23-2024 12:27 AM Edited on 04-28-2025 04:34 PM
Description |
This article describes how to deploy FortiAuthenticator in Active-Passive High Availability (HA) on VMware ESXi deploying two FortiAuthenticator VMs, configuring their network interfaces for heartbeat communication, and setting up HA to ensure redundancy. |
Scope | FortiAuthenticator. |
Solution |
Step 1: Deploy FortiAuthenticator VMs on VMware ESXi using OVA templates. To deploy FortiAuthenticator VM on VMware ESXi refer to this article: Technical Tip: How to deploy FortiAuthenticator in High Availability (HA) on VMware ESXi.
Step 2: Configure VMware Network for Heartbeat:
Create a vSwitch for heartbeat In Networking -> Virtual Switches, add a new virtual switch.
Create a VM Port Group for Heartbeat: In Networking -> Port Groups, add a new port group (HA_PORTGROUP) and associate it with the vSwitch created for HA communication.
Assign Portgroup to VM Interfaces:
Step 3: Configure Fortiauthenticator interfaces: On FortiAuthenticator, configure an IP address on Port1 for Management and Data traffic and configure Port 3 For HA:
Step4: Configure HA setup on FortiAuthenticator:
Repeat the same configuration on the Secondary firewall and set the priority as low:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.