Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ByteHaven
Contributor

Fortimail HA

Hi everyone,

 

I would like some clarification regarding FortiMail HA in active–passive mode, specifically around IP addressing and routing/firewall configuration.

 

I already know how to configure HA itself, but my main question is about IP addresses:

  • In an active–passive HA setup, do both FortiMail units use the same IP address, or does each unit keep a different IP address?

  • I currently have a Virtual IP configured on my firewall (192.168.1.1) to forward SMTP traffic.
    At the moment, the primary FortiMail has IP 192.168.1.1(which is the VIP), and the secondary FortiMail has IP 192.168.1.2.

  • SMTP traffic is currently being forwarded correctly to the primary unit.

My concern is failover behavior:

  • What should be configured so that when the primary FortiMail goes down, the secondary automatically takes over?

  • Once HA is configured and synchronized, does the secondary automatically take over the primary’s IP address (192.168.1.1), or do I need to modify something on the firewall side (VIP, routing, etc.)?

I want to make sure there is no mail disruption during a failover.

 

Thanks in advance for your help.

1 Solution
AEK

External to Fortimail:

  • Src intf: WAN
  • Dst intf: DNZ
  • Src: ALL
  • Dst: VIP (the VIP object created at FGT level)
  • Svc: SMTP, SMTPS

Fortimail to external:

  • Src intf: DMZ
  • Dst intf: WAN
  • Src: FML_VIP (probably you'll also need to add the 2 static IP addresses as well)
  • Dst: ALL
  • Svc: SMTP, SMTPS
AEK

View solution in original post

AEK
10 REPLIES 10
ByteHaven

Thank you so so much for your help AEK. You're a saint.

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors