Hi community,
I have a doubt regarding FortiGate HA active-active mode. There are some articles explaining this mode operation, I have taken this one:
https://www.fortinetguru.com/2016/10/natroute-mode-active-active-cluster-packet-flow/
Briefly and without going into too much 3-way handshake detail, when the primary unit decides that the subordinate unit should handle a packet, and forwards it to the subordinate unit internal interface, the primary unit forwards further packets in the same session to the subordinate unit. Is that correct? If so, every packet of the same sessión will pass first through the primary unit and then through the secondary unit? If so, then will link 1 be much more loaded than link 2?
Regards,
Julián
Hello,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello,
We are still looking for someone to help you.
We will come back to you ASAP.
Thanks
Hello fjulianom,
I found this solution. Can you tell me if it helps, please?
Yes, your understanding is correct. In an active-active HA setup, the primary unit is responsible for receiving all incoming packets. When the primary unit decides that a subordinate unit should handle a packet, it forwards the packet to the subordinate unit. Here’s a brief explanation:
This setup ensures that session information is consistent and synchronized across the cluster, but it does mean that the primary unit handles more traffic as it processes or forwards all incoming packets.
User | Count |
---|---|
2571 | |
1364 | |
796 | |
651 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.