| Description |
This article describes that sometimes, redundancy is required in a network. While two stand-alone firewalls can provide redundancy, asymmetric routing is required in this stand-alone design to ensure no packets are dropped due to session issues.
While asymmetric routing is a good workaround, it is not the best security practice, as some packets are not subjected to UTM checks. |
| Scope | FortiGate. |
| Solution |
In HA active-passive HA setups, the standby firewall is not actively processing traffic, so asymmetric routing is unlikely. To configure an HA active-passive HA setup, refer to the relevant documentation.
Change the FortiOS version as required. For example, HA active-passive cluster setup:
Note:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.