Hello, I'm new here and have a problem (of course ;) ) We're working on a new setup that is using 2 3960E (FortiOS 6.0.6) in an ACTIVE/STANDBY HA. I've attached a very rudimentary design that hopefully helps to understand what I'm trying to describe. The FWs are connected via OSPF to 2 multilayer switches via 2 transfer VLANs. The clients in this setup use the Firewall as a Gateway und the multilayer switches are gateways (HSRP) for the servers. The whole setup is a 100% symmetric which means that both transfer VLANs are in the routing table of the firewall with the same metric and distance. With ECMP active we have some weird effects regarding dynamic routing: When a client tries to reach a server, i.e. ping, the connection can take either VLAN towards the server and come back over the other VLAN. This behaviour itself is not unusual and actually desired but the Fortigate behaves weird when this happens. First of all the fortigate does not produce a log entry for this connection only for the ones where both packets take the same way. Secondly there is no NPU offloading for this session. Mind you the ping still works but the behaviour is still bothersome. For other connection types (i.e. HTTPS) we sometimes witness unsuccessful connections when dynamic routing is active, whenever we deactivate one of the transfer VLANs everything works a ok again but this can't be the solution. I hope I was able to describe our issues and hope somebody has an idea of how we can tackle this beast. Thank you so much
Kind regards
Searchingforanswers
What does "diag debug flow" show you. The issues seem to be related to session monitor and possible spoof'ing due to the nature of the traffic and 2 paths.
Can you possibly use SDWAN here ? If answer ="NO" Any reason as to why not ?
I think "ECMP" has it benefits but here I would not use it.
Ken Felix
PCNSE
NSE
StrongSwan
Hi Ken, thank you for your reply. Which benefit would we have using SDWAN? We do have to use OSPF because later we will connect some other branches that already are using ospf and we would like the firewall to distribute the client networks that are directly connected. We specifically want to use ECMP to distribute the load.
Thanks a again
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.