Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
RobinR06
New Contributor

Fortigate 100f Active-Passive HA not working as expected

Hello everyone,

 

we have recently bought two Fortigate 100f Firewall and set them Active Passive HA mode.

One would expect 1 Firewall to be active and 1 to passive, as the name suggests. But it looks like both are active?

The thing is, if I attach a Layer2 Switch with an IP address to FW1, it works and I can ping it. Just like expected.
If I connect the same Switch to FW2 only, it works and I can ping it. Strange, because FW1 is active?
If I connect the same Switch to FW1 and FW2 (for redundancy) my networks goes down, my laptop hangs and I cannot ping a thing. So looks like a double IP address issue. 

So what am i doing wrong? Or do I not get how Active-Passive is suppose to work?thumbnail_image.png

13 REPLIES 13
RobinR06
New Contributor

Thanks all for the help. I figured out the problem is not really in HA, but in the Hardware Switch.
We have configured a Hardware Switch with ports 5, 6, 7 and 8.
We thought Active-Passive means 1 firewall works, and 1 is passive. But If we pull out 1 device on the active firewall, the port on the secondary firewall becomes active. So the passive firewall port takes over.

And if we put a device on both firewalls, the whole setup reacts like one big hardware switch (instead of active/passive) and we get a loop as if it is a normal switch.

JesperAP

Hi Robin,

 

I am currently having the same issue I think,

 

Can you explain how you fixed it with the hardware switches?

Toshi_Esumi

@JesperAPMost unlikely your network set up with two FGTs and external switches as well as hardswitch setup is the same with the original poster's.
Please start a new thread and explain your HA problem in detail hopefully with a diagram so that anyone can contribute to resolve your issue.

 

Toshi

RobinR06

Hi Jesper, we still have not resolved the issue properly.
What we did is place some normal dumb switches between the Fortigates and the rest of the network. So we don't use the firewalls als switches anymore.

Labels
Top Kudoed Authors