Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
fjulianom
New Contributor III

FortiGate HA Active-Active mode

Hi experts,

 

In my work I have never seen two FortiGates in HA Active-Active mode, always Active-Passive mode. There is documentation for both modes, but the Active-Passive is always more common. According to me Active-Active mode is better since it provides redundancy, like Active-Passive, and also load balancing, unlike Active-Passive, which I guess it enhances the performance of the two FortiGates. Why is Active-Passive mode more common? Is there any downside of using Active-Active mode?

 

Many thanks in advance,

Julián 

3 Solutions
emnoc
Esteemed Contributor III

So where do I start ;)

 

1st

 

Active-Active does not provide load-balancing for ALL sessions ( you will not gain LB unless you had security-profiles and proxy  profiles enable for all traffic types )

 

2nd

Active-Standby is the more simple approach and yes offers hit-less failover if session replication is done  ( SSLVPN is ????s and will take a hit  btw )

 

3rd

if you have  multi-vdom, vcluster1+2 is  more widely supported and achieve load-sharing across both units in multi-vdom

 

 

 

 

PCNSE 

NSE 

StrongSwan  

View solution in original post

PCNSE NSE StrongSwan
emnoc
Esteemed Contributor III

http://help.fortinet.com/fos50hlp/56/Content/FortiOS/fortigate-high-availability/HA_FGCP.htm

 

 

Go down to section load-balance, in v5.4 and newier is slightly better, but just enabling "A-A" is  not going to give you 50/50 load-balance. Some session an traffic will always stay on the "master" unit. You can monitor session counts across the HA cluster to validate this YMMV.

 

Also google "set load-balance-all" fortigate

 

PCNSE 

NSE 

StrongSwan  

View solution in original post

PCNSE NSE StrongSwan
emnoc
Esteemed Contributor III

and  review this, this FTNT on document on HA  A-A and with tcp traffic

 

http://kb.fortinet.com/kb...D31790&languageId=

PCNSE 

NSE 

StrongSwan  

View solution in original post

PCNSE NSE StrongSwan
5 REPLIES 5
emnoc
Esteemed Contributor III

So where do I start ;)

 

1st

 

Active-Active does not provide load-balancing for ALL sessions ( you will not gain LB unless you had security-profiles and proxy  profiles enable for all traffic types )

 

2nd

Active-Standby is the more simple approach and yes offers hit-less failover if session replication is done  ( SSLVPN is ????s and will take a hit  btw )

 

3rd

if you have  multi-vdom, vcluster1+2 is  more widely supported and achieve load-sharing across both units in multi-vdom

 

 

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
fjulianom
New Contributor III

Hi Emnoc,

 

Thanks for you interest. I didn't know these three points. Could you please clarify the first point? It is not clear to me yet.

 

Regards,

Julián

emnoc
Esteemed Contributor III

http://help.fortinet.com/fos50hlp/56/Content/FortiOS/fortigate-high-availability/HA_FGCP.htm

 

 

Go down to section load-balance, in v5.4 and newier is slightly better, but just enabling "A-A" is  not going to give you 50/50 load-balance. Some session an traffic will always stay on the "master" unit. You can monitor session counts across the HA cluster to validate this YMMV.

 

Also google "set load-balance-all" fortigate

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
emnoc
Esteemed Contributor III

and  review this, this FTNT on document on HA  A-A and with tcp traffic

 

http://kb.fortinet.com/kb...D31790&languageId=

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
fjulianom
New Contributor III

Hi Emnoc,

 

Many thanks, I will check those documents.

 

Regards,

Julián

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors