Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
justindavidson
New Contributor

FortiGate 601e MultiSite HA with dissimilar internet connections

Has anyone setup Multisite HA? We have a 10GB dark fiber connection to a remote site that "extends" our broadcast domain and would like to set a secondary Fortigate there for redundancy. We also have an internet connection there and would like to use it should the main site lose the web. My concern is that the main site has an Internet subnet of X.X.X.X and the redundant site has an internet subnet of Y.Y.Y.Y. Would that make the HA have issues as they dont have the same interfaces up? 

2 REPLIES 2
ede_pfau
SuperUser
SuperUser

I've previously set up a multisite a-p HA across 2 datacenters in a big city. Dark fiber is very helpful in this. Lately, as of FortiOS 6.4 and later, HA links do work over Layer 3 networks.

 

For one, you can (almost) always use the same (private) IP range for the transit network between FGT wan interface and ISP CPE device. That would make the config identical.

 

But, if you use the public WAN IP(s) for access to internal servers, like for VPN, website etc., then you need to work out WAN address transfer with your ISP. This will probably only work (if available at all) only if both sites are on the same ISP.

 

We managed to achieve this using VRRP between both access routers. When testing, the FGT failed over within 1-2 seconds, the routers and the WAN address relocation took like 15 minutes...but it worked.


Ede


"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
justindavidson

There is an ISP for only the Internet circuits at each site (Which is the same ISP, but different routes for protection). The dark fiber is ours and no vendor involved so we have full control. 

Each site has an internet circuit but the IP subnets are different. 

Labels
Top Kudoed Authors