Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Alex_talmage
New Contributor

Experience with Load Balance Slaves?

Hi All,

 

Loving our FortiAuthenticator. Currently have two VMs running Active/Passive HA on version v4.00-build0081-20160601-patch00. We've got 64 VPN users, and 23 RADIUS clients for 2FA for IT Administration. This is in our UK function.

 

We are looking at rolling FortiAuthenticator out in the US function also, and one feature that caught my eye was the Load Balance slave feature. So my understanding (please correct me if I'm wrong), is that we could spin up another 2x FAC VMs in the US, in a separate HA A/P cluster, and set that cluster to be a Load Balance slave of the existing UK HA cluster. The bit I'm not too sure of is what functionality this would give us, and how licensing would work?

 

Is my understanding correct?

1. Our VPN users would be configured on the UK end which would sync to the US end. We would need a license per user on each?

2. In the event that we lost our site to site connection, US users would continue to authenticate via US and UK would authenticate via UK.

 

Questions:

1. How are RADIUS clients handled? Are these synchronised between the two, or would I need to point US devices to US fortiauth and UK devices to UK fortiauth?

0 REPLIES 0
Labels
Top Kudoed Authors