Hi,
I have 2 Q regarding to Fortigate A/P.
Now I have my 901 FG with a dedicated port for HA. I will make this port for Heartbeat. And I do have 2 fiber links as well for HA with normal ports. Is the best practice to keep the HA default port for heartbeat sync, and use the 2 extra fiber ports for session sync only?
Or there is no way to segregate between heartbeat and session synchronization, so I have to keep all of them in the heartbeat option?
The second question is, I have enabled the HA with no license on my firewalls when I want to add the license for my firewalls. Is the correct way to remove HA back to standalone mode and then enable the license on each box and return to A/P mode?
thanks
Yes, at least 7.4.8 admin guide described it below under "Using multiple FortiGate interfaces for session synchronization" section.
Toshi
Yes, the 7.4.8 Admin Guide explains this under the “Using multiple FortiGate interfaces for session synchronization” section. You can find the details in the Improving session sync performance documentation.
User | Count |
---|---|
2546 | |
1354 | |
795 | |
643 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.