FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
DPadula
Staff
Staff
Article Id 268820
Description This article describes how to configure HA A-P mode with VDOM partitioning.
Scope FortiOS 7.0.x and above.
Solution

In some network environments with a pair of FortiGate in HA A-P mode with two or more VDOM, it is possible to make some of the VDOMs active in one of the primary FortiGate and other VDOMs active on the secondary FortiGate.

 

This is called virtual clustering with VDOM partitioning:

 

Diagram.PNG

 

Step 1: Check if the HA is in sync. This can be checked under System -> HA

 

Devices in Sync.PNG

 

Step 2: Select the Primary device and select Edit and then enable VDOM Partitioning. The GUI should look like the one below.

Note that only one virtual cluster exists at this stage. 

 

enable vdom partitioning.PNG

 

Step 3: Select Create New then select the VDOMs to be migrated to the virtual cluster 2. In this example, The VDOM TEST has been created as part of the virtual cluster 2. Select OK.

 

create new virtual cluster.PNG

 

Step 4: The GUI will show two clusters and their respective VDOMs. Virtual Cluster 1 with PROD and root, Virtual Cluster 2 with TEST. Select OK.

 

HA 2 clusters.PNG

Step 5: GUI should show the HA page with FortiGates out of sync. 

 

Secondary FGT out of sync.png

 

Just select Refresh before proceeding.

 

Secondary FGT in sync.PNG

Step 6: Select the TEST VDOM on secondary FortiGate (FW-SEC) and increase the priority to mate it primarily. 

 

vdom partitioning complete.PNG

 

Now traffic to TEST VDOM will be handled by FW-SEC and traffic to PROD and root VDOMs will be handled by FW-PRI. 

 

Related articles: