Description
This article describes how to deploy and configure active-passive HA within one zone.
Solution
It is possible to configure FortiGate's native active-passive HA feature (without using an Azure supplementary mechanism such as Azure LB) with two FortiGate-VM instances: one acting as the primary node and the other as secondary node, both located in the same region.
This is called unicast HA and is specific to Cloud environments including Azure.
Unicast HA complies with Clloud environments' network restrictions as compared to equivalent features provided by physical FortiGates.
The FortiGate-VMs run heartbeats between dedicated ports and synchronize OS configurations.
When the primary node (FortiGate Node-A in the diagram), the secondary node (FortiGate Node-B) takes over as the primary node so endpoints on a protected server continue to communicate with external resources over the FortiGate.
The public IP addresses shown in the diagram will differ from the used IP, configured during deployment.
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.