Hi Guys and Gals,
Having some difficulty working out what best practices are for multiple switches in a HA A-P cluster.
At site 1 we have the following setup
At site 2 we have the following setup.
When I change site 1 to match site 2 we get a broadcast storm and another strange issue where the switch ports on the secondary fortigate start giving DHCP/internet access, needless to say things didnt work and we reverted to the original topology.
The only difference is STP is turned on in the hardware switch settings for the fortigate other than that everything else is the same. I've checked and I dont see a loop anywhere in the rack or on the floors. Why is this config that works at one site not working at another?
What is the best practice for an A-P cluster, if I have the switches connected like site 1 will clients connected to both switches retain network and internet access if the secondary fortigate takes over?
Site 1 images does not show up
Orestis Nikolaidis
Network Engineer/IT Administrator
click on the link please, I could not get it to display in the thread.
Hi!
Did you configure the links to the switches on each FG as A/P-Bond, or did you just switch them?
the links to the swithes on each fortigate are just standard ports that are part of the hardware switch on the interfaces page.
how do I AP bond them, are you referring to a creating a redundant interface.
Hi In short, yes the secondary will take over, depending on the confgured monitors.
Best practices in A-P isn't to crosscabling the Fortigates.
________________________________________________________
--- NSE 4 ---
________________________________________________________
Hi!
I would always prefer redundant cabeling. Using a failover-bond is easy and does not force a failover in case of a switch-reboot...
could you give a diagram of this redundant cabling, when I cable things as per the fortinet diagram I get a loopback?
Thanks for the diagram, can you explain the purpose of the third switch on the LAN side closest to the host machines.
So shuld I be putting a small switch in between each fortigate and our main LAN switch, how do I connect a second lan switch in this case?
I need two switches here as we have more than 48 patch ports to link up.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1740 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.