I'm hoping someone will be able to help with this query.
I'm looking at implementing a pair of Fortigate 500D firewalls within an MPLS network.
They will be installed in two geographically separate data centres.
Two of the key requirements are configuration synchronisation and session pickup, and unfortunately the Fortigate documentation is a little sparse in this area (to say the least!).
It would seem that FGSP will meet the requirements but my concern is around the synchronisation link. I can't determine if both ends of this link need to be in the same broadcast / subnet or if is it possible to route this traffic over a layer three network.
If someone could confirm either way I'd be very grateful.
Again, there is little documentation around how much traffic session pickup generates over the synchronisation link, so if anyone has got any information at all on this I'd really appreciate it.