Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Wh1teWolf
New Contributor

Connect two Fortigate HA-Clusters directly

Hi everyone,
I have the following scenario:

Two Fortigate HA clusters (active/passive |100E v7.2.10) are currently in operation in the customer environment. The two clusters are currently connected by a fiber optic cable. A transfer network and an IPSec VPN have been configured between the links. If an HA failover occurs on one of the clusters, the other cluster must always switch over so that data traffic can continue, because there is only one link between the firewalls.

 

Now the links between the firewalls will be expanded to four, as shown in the image below.

Unfortunately, there is no switch in between, so the firewalls need to be connected directly to each other.

 

My first thought would be to configure an additional IPSec tunnel on both clusters via port 15 and put both IPSec tunnels in an SD-WAN zone. Adjust routing and policies on the SD-WAN zone. Health checks via ping on peer tunnel IP and in SD-WAN rule tunnel via port 16 should be preferred and port 15 backup.

Would that be a viable option, or is there perhaps an alternative solution?

 

13-01-2026_16-19-46.png

 

3 REPLIES 3
AEK
SuperUser
SuperUser

Hi

Did you try with software switch / hardware switch?

AEK
AEK
Wh1teWolf
New Contributor

Nothing has been configured yet; I am still in the planning phase.

Ialso thought about that option, but I wasn't sure if it would work. Testing is a little bit difficuilt because it's an productive environment and i haven't two test ha clusters.

Toshi_Esumi
SuperUser
SuperUser

I wouldn't try direct connections, which could/would cause headaches, if not trouble, in the future. A decent 8 port switch isn't too expensive.

Toshi 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors