Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Johnnyb1984
New Contributor

Connecting to mgmt of subordinate firewall in active-active HA

We have 2 Fortigate 200F firewalls configured in an active active HA cluster. We are on firmware version 7.0.6. At the moment I can connect to the SSL VPN and browse to the mgmt UI which is always the active firewall. We want to be able to connect to the UI of the subordinate firewall.

 

I have tried configuring the Management Interface Reservation under the HA settings but I am unable to connect to the ip address configured. The traffic seems to be getting blocked buy the access policy and I am unable to create a policy for the mgmt network interface.

 

I also tried using the set management-ip command on the interface I wish to use. I then connect to the cli of the subordinate firewall and give it a different mgmt ip in the same network. Using this method I can create an access policy and I can connect to the active firewall but not the 2nd firewall. From looking at the logs it seems the traffic is being routed to the WAN interface. The port I have configured is connected to the same port on the 2nd firewall. 

 

 

1 REPLY 1
Patterson
Staff
Staff

Hi,

kindly check  the topology, there are two traffic management  and  production traffic. These are in different vrf, Please refer the below KB explaining the same in detail.

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-HA-Reserved-Management-Interface-s-hidden-...

Regards,

Patterson

Regards,
Patterson
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors