When we configure the fortigate as Active-Active this mean we will have :
Now i want to focus 2 cable from fortinet to the LAN. Should the LAN ip address on the fortigate side have different ip or same ip? If use same ip address, what should we configure on the core switch port? Should 2 ports on the core switch configured as L3 LACP, or should we configure as L3 but using VLAN?
Hi @HS08
On HA Active-Active scenario there should be different IP on LAN connection.
Please review the following guide and article:
https://docs.fortinet.com/document/fortigate/7.2.10/administration-guide/357558/ha-active-active-clu...
https://community.fortinet.com/t5/FortiADC/Technical-Tip-How-to-failover-traffic-group-to-the-other-...
BR
Hi @ndumaj
I can't find any guide that we should use different i address on LAN for active active scenario. Can you help me by give the screenshot maybe?
Hi HS08,
Please refer below article for deployment.
https://docs.fortinet.com/document/fortigate/6.2.16/cookbook/357558/ha-active-active-cluster-setup
Hi @sjoshi
Already read the article, but still confuse related ip address configuration for active active scenario. Should each LAN interface from fortinet use same ip address or different ip address?
Both the FGT will have the same IP address for all interface
How about the mac address, will be same or different?
Refer:-
you can refer above article and go through it once..
After that if you have still any query let me know
 
					
				
				
			
		
| User | Count | 
|---|---|
| 2678 | |
| 1412 | |
| 810 | |
| 703 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.