Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
HossamAdel
New Contributor

HA Active Active with IPSEC & SD-WAN

Hello, I'm going to Configure HA active-active but currently I have SD-wan "5 members" with multiple IPSec VPN & my question about 1 - Could I connect each Fortigate directly to the router or via Switch ?  

2- If I use a switch between HA & routers? in this case how to configure Static(public) IP ? 3- Regarding IP-SEC VPN it will be configured on the primary device only ? right , Due to Endpoint gateway IP so no load balance for VPN.   

1 REPLY 1
nomeursy
New Contributor III

1 - Could I connect each Fortigate directly to the router or via Switch ?

that depends on the router, if the router has a build-in switch port you could do this. If the Router has only 1 LAN port, then you need a switch to connect 3 ports to the same Layer-2 domain. Be careful not to use 1 switch to connect all routers and FTG’s together even when using VLAN’s per connection, because you will introduce a single point of failure, the switch.

 

2- If I use a switch between HA & routers? in this case how to configure Static(public) IP ?

In Active-Active you only configure the Primary Fortigate, the config will be synchronized to the Secondary, so except the HA settings the config will be the same.

 

3- Regarding IP-SEC VPN it will be configured on the primary device only ? right , Due to Endpoint gateway IP so no load balance for VPN.   

Yes once the HA config is done and the Fortigates are Up and in sync, you only configure the Primary FTG.

In HA Active-Active the following sessions are processed by the primary unit & not load balanced: UDP, ICMP, Multicast, Broadcast, VoIP, IM, P2P, IPSEC VPN, HTTPS, SSL VPN, HTTP Multiplexing, SSL Offloading, WAN Optimization, Explicit Web Proxy & WCCP sessions.

Labels
Top Kudoed Authors