Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Asanka
New Contributor

Fortigate 300C HA in Active – Active mode with Cisco 3750X Stackable switches

Hello All, I am planning to implement Fortigate 300C HA in Active – Active Mode with Link Aggregation (LACP 802.3ad) for four firewall segments with full mesh. Two Firewall segments will connect through Cisco 3750X Stackable switches and one segment will connect via Cisco 2960S Switch stack. Two Firewall Segments will be defining as several VLANs under Ethernet bond (LACP) interfaces. If anybody has experience in deploying Fortigate Active – Active HA with Cisco 3750X & 2960S stackable switches Please verify above and comment. Tnx, Asa
Asanka
Asanka
6 REPLIES 6
emnoc
Esteemed Contributor III

I' m kinda of doing that with 620B now, but with a 3750E stack, what' s your concerns? The stack allows for multi chassis lacp, so you can create redundancy in the stack. Bothe A-A pairs will need 2 links minimum into each stack switch and then those ports for each firewall will need LACP enable. What we did was craft a LAN topo of 2x3750E for the outside and dmz and then the internal lan topo from the 620B goes back into our Nexus 7K core. We have 2 FGT one set specifically as a VPN terminator for remote-clients and site2site vpns. Other than cpu seems higher on one FGT than the other, we haven' t seen any real issues. It was kinda over kill, but they had the budget.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
FortiRack_Eric
New Contributor III

Works like a charm, no special issues, you can make a LACP from a cluster node to the stacked Cisco' s (split over the 2 units). No special issues.

Rackmount your Fortinet --> http://www.rackmount.it/fortirack

 

Rackmount your Fortinet --> http://www.rackmount.it/fortirack
Asanka
New Contributor

Thanks " emnoc" & " SecureLayers-Eric" for you inputs !! Since Fortigate HA operates on Virtual MAC address.. in case of failure occurs on Switch stack , network segment or firewall level, will there be significant delay in fail-over or is it normal like (one ping request timed out)?? And what is your recommendation on configuring ether channel for this setup from Cisco Stack side? Regards Asanka
Asanka
Asanka
emnoc
Esteemed Contributor III

How much of a impact? could be determine by how much traffic over that link. Nobody can give you an exactly ms or sec impact or lost of ping count. Just test it, it will be minor if any.And hardly noticeable. On etherchannel mode, you want LACP so channel-group x mode act is what I would do. X would be the port-channel number & this enable LACP aka 802.3ad on whatever members you deploy. One last issue, On the channel-groups load balancing, you might want to monitor & adjust the balancing algorithm. Execute the " show etherchann load-balance" command to get any ideal of the default load-balance schema. Then adjust accordingly, src/port-dst/port ( L4) is typically better than src-mac or dst-mac or src-ip/dst-ip ( L2 or L3 respectively ). EtherChannel Load-Balancing Configuration: src-dst-port mpls label-ip EtherChannel Load-Balancing Addresses Used Per-Protocol: Non-IP: Source XOR Destination MAC address IPv4: Source XOR Destination TCP/UDP (layer-4) port number IPv6: Source XOR Destination IP address MPLS: Label or IP YMMV

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Asanka
New Contributor

Thanks for the inputs!! I have tested mention scenario in-house using two standalone Cisco switches (one channel group per LACP Bond interface) for two segments with Full mesh , LACP & Session Pickup from Fortigate HA side. i have tested failover by powring off Master fortigate unit while ICMP Ping & FTP Filtransfer in place between two segmnts. when power goes off in Master unit FTP seesion & ping ( 1 time out) still working without issue. But when i power on the (Previous Master) Unit again ofter about 20 -30 sec all active connection get drop (ping & ftp) for 10 - 20 sec. and start working again during this time HA master role will be taken by previous master unit. but all active connections get drop !!!! Regards, Asanka
Asanka
Asanka
emnoc
Esteemed Contributor III

That' s has nothing to do with LACP btw. You might want to look at HA and how it works and preemption & override.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors