Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jmillsapps
New Contributor

FortiGate 200F HA internet loss

I have 2 - FG 200F's. I have HA configured. I have 1 FG WAN connected to a modem going to fiber internet. My 2nd FG WAN is connected to a modem going to COAX internet. So, 2 different internet pipes. "FG1" is primary, "FG2" is secondary. While in this configuration, I can access and ping the internet from each firewall. When I force an HA failover, "FG2" becomes primary as expected, however, once it does, I lose internet access and can no longer ping anything on the internet (from "FG2" via CLI). I am not sure what I am missing.

 

FW: v7.4.4 build2662 (Feature)

Active-Passive

HA.png

1 Solution
AEK

You can do this and other nice things with SD-WAN.

You may start here:

https://docs.fortinet.com/document/fortigate/7.4.4/administration-guide/19246

Hope it helps.

AEK

View solution in original post

AEK
10 REPLIES 10
AEK
SuperUser
SuperUser

Is it active passive HA?

Do you have dedicated management on this HA?

If the passive node still ping internet when it is passive then it is most probably pinging from its mgmt interface.

Why using different WAN links on your nodes. Why don't you use both WAN links in both nodes?

AEK
AEK
jmillsapps
New Contributor

Yes, I have a dedicated management port on each firewall.

I have one WAN link per firewall.

jmillsapps
New Contributor

I just did some testing, and saw that even though I was connected to the "passive" node and pinging the internet, a traceroute showed that I was pinging via the internet that the primary was connected to.

AEK
SuperUser
SuperUser

You should connect modem1 to the same port of each FortiGate (lets say to wan1 port).

And connect modem1 to the same port of each FortiGate (lets say to wan2 port).

In case your modems don't have multiple ports (integrated switch), then you need to use a L2 switch to connect them to your FortiGates.

AEK
AEK
jmillsapps
New Contributor

Thanks! I will try this and follow up.

jmillsapps
New Contributor

So, in the diagram below, is this the correct configuration? Both firewalls, WAN1 goes to one modem, and WAN2 goes to the backup internet modem?

HA -2.png

 

AEK

Yes that is much better.

AEK
AEK
jmillsapps
New Contributor

Thanks! I will try this after hours over the weekend and follow up with results. Thanks again for the assistance!

jmillsapps
New Contributor

I understand this would work if one firewall goes offline or loses power, but will it still work if one of the internet pipes goes offline. How will the firewall know to switch to the other internet?

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors