Hi
A couple of questions about Fortimanager HA cluster behavior;
1- Per to guides, they stated that:
[style="background-color: #ffff00;"](If the primary FortiManager unit fails you must manually configure one of the backup units to become the primary unit.[/style] [style="background-color: #ffff00;"]The new primary unit will have the same IP addresses as it did when it was the backup unit.)[/style]
Does this mean that there is no auto-failover, and the backup unit will not get the primary unit IP address?
[style="background-color: #ffffff;"] [/style]In this case the managed devices will loss connectivity to FM and we have to build a new connection based on the backup unit IP...
2- when configuring HA, does every node keep its interfaces IPs, or they will share the primary unit interfaces IPs?
Thanks
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
> Does this mean that there is no auto-failover, and the backup unit will not get the primary unit IP address?
Correct. You must manually promote one of the slave FMG units to the master role. Each cluster member has a unique IP]
> In this case the managed devices will loss connectivity to FM and we have to build a new connection based on the backup unit IP...
Yes, unless you have configured the FortiGates with multiple FMG IPs, a feature introduced into the FortiOS CLI starting in FortiOS 5.6.
> 2- when configuring HA, does every node keep its interfaces IPs, or they will share the primary unit interfaces IPs?
Separate IPs
> Does this mean that there is no auto-failover, and the backup unit will not get the primary unit IP address?
Correct. You must manually promote one of the slave FMG units to the master role. Each cluster member has a unique IP]
> In this case the managed devices will loss connectivity to FM and we have to build a new connection based on the backup unit IP...
Yes, unless you have configured the FortiGates with multiple FMG IPs, a feature introduced into the FortiOS CLI starting in FortiOS 5.6.
> 2- when configuring HA, does every node keep its interfaces IPs, or they will share the primary unit interfaces IPs?
Separate IPs
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.