Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
hawada
New Contributor

Converting high-availability from active-passive to active-active

Hello,

 

Is it possible to convert Fortigate mode from active-passive to active-active in a productive network.

 

thanks

1 Solution
Carl_Wallmark

you still need one high and one low priority. So you can just leave them as is. (I assume you have one high and one low)

 

Even if you have active-active, the two firewalls will still be "master-slave"

 

All traffic will hit the master first, then the master will distribute the sessions to it´s slaves.

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

View solution in original post

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
4 REPLIES 4
Carl_Wallmark
Valued Contributor

Yes, it´s very easy, just select active-active and click ok.

 

However, there might be a few seconds of downtime while they are changing mode.

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
hawada

Thanks for your quick reply.

 

But what about Device priority and override option.

I should modify device priority to be the same on both fortigates?

 

Thanks

Carl_Wallmark

you still need one high and one low priority. So you can just leave them as is. (I assume you have one high and one low)

 

Even if you have active-active, the two firewalls will still be "master-slave"

 

All traffic will hit the master first, then the master will distribute the sessions to it´s slaves.

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
hawada

Thanks again for your support, it is very hepful.

Labels
Top Kudoed Authors