I have an 2 seperate HA Active-Passive Cluster of Fortigate Firewalls.
I want to connect the first cluster to other cluster without introducing any switches in between in a full mesh connectivity. This is required to achieve full redundancy between the 2 HA clusters.
What is the best practice in achieving the above? Is creating Redundancy Interface and add 2 10GB port to this interface on both will do the job?
Please check if FGSP clustering between the current clusters is the solution for you.
https://docs.fortinet.com/document/fortigate/7.2.4/administration-guide/668583/fgsp
Regards,
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.I have checked the document shared.
Actually what I am trying to achieve is connect 1 HA Cluster (Active-Passive) (Site-A) to another HA Cluster (Active-Passive)(Site-B) through direct fiber cables in a full mesh.
Can you confirm how is the traffic flow through these 2 clusters? A full mesh HA is to avoid a single point of failure in network, something like below.
In your setup, you have 2 HA, are they redundant to each other? If so, how is the sessions synced between them and how is the traffic flow.
Regards,
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.Is there a reason you don't want to use switches in between?
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.