Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Carl_Wallmark
Valued Contributor

Experience with Fortigate HA and HP Procurve switches?

Hi, I have 2 FG 200A set up in a HA and with alot of VLANS, Does anyone have any experience with HP Procurve (2600) switches and trunking between FG and Switches, i´m having a bit problem with how to configure trunking on the switch, its working when i have Trunk1 to one of my FG and Trunk2 to the other but not when Trunk1 is connected to both. Is there anyone who have a working setup like this ??

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
14 REPLIES 14
Carl_Wallmark
Valued Contributor

i called HP yesterday and they said that it would be impossible to have 2 trunks (same trunk) to one device, i don´t know if he know what he was talking about, but this can´t be right ??? can it ?

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
UkWizard

Selective - I think the key to that answer is the fact you said " one device" . as this implies you are trying to get two trunks to a single unit. You are now really, its two units. so i would of expected it too work somehow. doshbass - not sure what you mean, as he has one switch, not two. and the clustered pair of fortinets would have numerous heartbeat interfaces anyway, outside of the internal network. that raises a good point though? Selective - how have you got the heartbeat set? do you have a dedicated cable between the two units as well? in a HA cluster you ideally need one, that should be the primary heartbeat, with another interface as the secondary heartbeat. let us know how you have this configured, even if its a screenshot of the HA settings page.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Carl_Wallmark
Valued Contributor

i told him that i had 2 firewalls and that they are clustered, but on the network they seem to be " one device" . the two FG are connected with a crossover cable from DMZ1 to DMZ1. The failover occurs correct when a shutdown one of the FG´s. can´t upload any pictures, i get " internal server error 500" i´ll try later.

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
UkWizard
New Contributor

try setting the cluster heartbeat traffic to just use the dmz1 port, this might prevent the firewalls from trying to chat through the switch.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
UK Based Technical Consultant FCSE v2.5 FCSE v2.8 FCNSP v3 Specialising in Systems, Apps, SAN Storage and Networks, with over 25 Yrs IT experience.
Carl_Wallmark
Valued Contributor

the heartbeat interfaces are directly connected with a crossover cable, they are not going through any switch

FCNSA, FCNSP
---
FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30B
FortiAnalyzer 100B, 100C
FortiMail 100,100C
FortiManager VM
FortiAuthenticator VM
FortiToken
FortiAP 220B/221B, 11C

FCNSA, FCNSP---FortiGate 200A/B, 224B, 110C, 100A/D, 80C/CM/Voice, 60B/C/CX/D, 50B, 40C, 30BFortiAnalyzer 100B, 100CFortiMail 100,100CFortiManager VMFortiAuthenticator VMFortiTokenFortiAP 220B/221B, 11C
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors