Created on 09-25-2022 09:05 PM Edited on 11-13-2024 07:17 AM By Jean-Philippe_P
Description | This article describes how to implement in-band management IP for HA Cluster. |
Scope | FortiGate v6.4, v7.0, v7.2, v7.4. |
Solution |
Direct management access is provided to each cluster unit by implementing an in-band management interface.
By default, HA will have only 1 (one) single IP management for a cluster. Therefore, only primary will be administratively accessible. The secondary is accessible via the primary device (see related documents).
Note. The in-band management IP address is an alternative to the reserved HA management interface feature and does not require reserving an interface just for management access. It can be added to existing cluster management IP or any other configured L3 interface.
The IP that will be used for in-band management should be a free IP of the same network range that is already configured on that interface and a valid route OR an IP which have a valid route into the routing table.
FGT1 – is the primary and FGT2 – is the secondary.
Now each device is individually accessible.
Note: Check the IP addresses are correctly showing up on both devices in the cluster. fnsysctl ifconfig port4 -> This would only show the configured IP address on the interface, not the management-ip diagnose ip address list | grep port4 --> This would show both IP addresses associated with port4.
Conclusion:
Related documents: Technical Tip: HA Reserved Management Interface Technical Tip: Managing individual cluster units with the CLI command 'execute ha manage' |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.