Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
orrsjo
New Contributor

Setting up HA on a FortiGate 60

Hello,   We have a scenario with two HA Fortigate units. I'd like to connect them to two stacked (Aruba) switches on the inside. However, as far as I know that model does not support LACP. So how do I connect the Fortigates to the switches? I have tred just to use a LAN-port (with DHCP) from each Fortigate to each switch, but I didn't get that to work. How should I configure that?   Regards, Erik
3 REPLIES 3
Toshi_Esumi
Esteemed Contributor III

We use FG60Dx2 in HA(a-p) at our office. We have a set of cisco switches with four trunk ports for the FGs; two (one for WAN another for LAN) coming from each FG. All IPs are configured only on VLAN subinterfaces at FGs and Cisco switches handle vlan-spanning and access ports for non-vlan devices.

emnoc
Esteemed Contributor III

if they are stack and don't support LACP, than you probably can't use   LACP for a HA measure?

 

What's your access-layer  layer3  structure? What's the local lan gateways  next-hop ( FGT or SWITCH )?

 

What I've done was to  use  layer3 at the l3-switch and run  dynamic routing protocol ( BGP/OSPF ) and you  adjust the  metric  for what link you want.

 

Look at this diagram

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
emnoc
Esteemed Contributor III

The  two downlink that have different  metric, will be cable to each stack member as a physical link if that's not  obvious, the layer3  router will send and receive ALL traffic over that link  to avoid asymmetrical  routing.

 

And only one FGT is active , this works for  near sub sec failover if the FGT200 fails or  links are unplugged.

VRRP is used at the local-LAN NET01/02/03 to  provide   LAN access and a combination of ip sla and track ensure you   control  master/standby  at the cisco l3-sw-SVI.

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors