I am looking for a detailed guide on HA setup, all I see on the Internet are basic setup steps.
I have a few queries with regards to HA on fortigate
1. Do I need to assign IP addresses on HA interfaces?
2. Do I need to setup the IP addresses on both firewalls for other (non-HA) interfaces? Is it going to get the IP from master during the fail-over?
3. How about MGMT interface in HA pair, do I need to assign IP on both firewalls?
They used to have a separate handbook only for HA but I can't find it any more. So check HA section of the handbook.
All answers should be in there but,
1. No, HB interface needs no IP
2. Regularly backup/slave unit don't need to configure anything else other than HA config and a few part, like MGMT interfaces, that wouldn't be copied over. During the sync up process after becoming a backup/slave, all the other config including interfaces will be copied over from master. Just make sure it would become the backup/slave by reading the primary selection flowchart.
3. You don't have to have an IP on MGMT interface if you don't plan to use outband managment. I use it when when the config becomes un-syncable from the master and needs a hand-modification and upload.
Thank you.
Is the MGMT interface out of band management?
If you configured it to be in HA config.
About this topic, I have a doubt. In HA setup the VRRP ip address is unique for the cluster but each Fortigate has an ip address.
When VRRP is working only the VIP is accesible and you can manage one Fortigate or other with: execute ha manage
This is right?
Well, imagine that:
FGT1 10.10.10.10
FGT2 10.10.10.11
VRRP 10.10.10.12
If one equipment overlap the ip address of (for example) FGT1.
There would be a problem?
What are the ips of each Fortigate used once the cluster is formed?
I hope to have explained.
Thanks
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.