Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Jason_Loera
New Contributor

Active-Active HA

Has anyone been able to successfully get active-active HA working with the 620B? I have a pair with the same software and can successfully establish a heartbeat and pass the configuration from the primary to the secondary, but then all traffic moving through the firewall stops. I' ve researched and troubleshot but cannot find a root cause.
3 REPLIES 3
Istvan_Takacs_FTNT

# diagnose sniffer packet any ' host <remote address you try to access>' 4 a and # diagnose debug flow show console enable # diagnose debug flow show function-name enable # diagnose debug flow filter # diagnose debug flow filter addr <remote address you try to access> # diagnose debug enable # diagnose debug flow trace start 10 and run some test. I assume FW policies and correct routes are in place.
norouzi
Contributor

You select Active-Active so all links of two fortigates should be connect to the same network.

Please use Active-Passive with kind of configuration that the your main device that is connected to all part of networks, be Active one. 

Then you can change the mode easily.

 

Fahad
New Contributor III

Hi,

 

when you configure HA in A-A the fortigate actually doesnt work in a-a it only shares the UTM traffic across both appliance, if you want it full a-a then from the CLI you have to type: config system ha --> set load-balance-all enable .

 

....

FCSNP 5, JNCIS-FW,JNCIA-SSL ,MCSE, ITIL.

FCSNP 5, JNCIS-FW,JNCIA-SSL ,MCSE, ITIL.
Labels
Top Kudoed Authors