I have an 2 seperate HA Active-Passive Cluster of Fortigate Firewalls.
I want to connect the first cluster to other cluster without introducing any switches in between in a full mesh connectivity. This is required to achieve full redundancy between the 2 HA clusters.
What is the best practice in achieving the above? Is creating Redundancy Interface and add 2 10GB port to this interface on both will do the job?
Please check if FGSP clustering between the current clusters is the solution for you.
https://docs.fortinet.com/document/fortigate/7.2.4/administration-guide/668583/fgsp
I have checked the document shared.
Actually what I am trying to achieve is connect 1 HA Cluster (Active-Passive) (Site-A) to another HA Cluster (Active-Passive)(Site-B) through direct fiber cables in a full mesh.
Can you confirm how is the traffic flow through these 2 clusters? A full mesh HA is to avoid a single point of failure in network, something like below.
 In your setup, you have 2 HA, are they redundant to each other? If so, how is the sessions synced between them and how is the traffic flow.
Is there a reason you don't want to use switches in between?
Hi,Do you have a solution for that issue,I live same problem?
Hi CEMS
Didn't test it and don't know if it is supported, but I think you can do it with a hardware (or software) switch interface.
i.e.: one each cluster you configure 2 ports as hardware (or software) switch, then you inter connect the two clusters via these ports, like shown below.
Many thanks AEK,Ye I can Hardware or Software Switch,actually I can Redundancy or 802.3 ag but I use HA Active(tus11,art11) and Passive (tus12,art12) How can trigger something happens ,in my scenario connection 1 from tus11emc to art11 is down How can I transfer traffic through to art12 emc ,I could not add software or hardware swtich interface ha monitor interface by the way ,I just add redundant or 802.3AG interface,should I configure wtih these interface or should I do ip sla
I guess you mean 802.3ad (aggregate).
For interface monitor you can't select hardware switch interface, but can monitor 802.3ad interface.
I think 802.3ad should also work as solution for your requirement, but you need to test it well, and also I don't know if this solution is supported by Fortinet, even in case it works well, so you may open a ticket to ask if it is supported or not.
User | Count |
---|---|
2249 | |
1222 | |
772 | |
451 | |
366 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.