Description | This article describes how to configure Virtual IPs on the FortiGate VM Active-Passive HA Cluster to have no issues if failover happens. |
Scope | FortiGate-VM, AWS-FortiGate, Azure-FortiGate, GCP-FortiGate, OCI-FortiGate, or any other FortiGate-VMs hosted on Public Cloud. |
Solution |
There are two different ways to implement VIPs on the FortiGate-VM HA cluster.
Diagram:
On Primary FortiGate:
Example1: On the Primary FortiGate (FGT-A):
config system vdom-exception edit 1 set object firewall.vip next end
On Primary FortiGate:
On Secondary FortiGate:
Example2: On the Primary FortiGate (FGT-A):
On the Secondary FortiGate (FGT-B):
Related documents: VDOM exceptions | FortiGate / FortiOS 7.4.3 | Fortinet Document Library. Virtual IPs with port forwarding | FortiGate / FortiOS 7.4.3 | Fortinet Document Library. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.