I have two FortiGate 200D in HA mode currently and need to transfer one of them to the DR location. DR Site IP range and HO IP ranges are the same. Core Switch with different VLAN is having a gateway set to firewall LAN IP.
Is it Possible to have an HA configured using Datalink connectivity between 2 different geographic locations?
Do any other Changes are required on the Core switch?
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
I've done this before, across a big city. No problem.
The main thing is that the HA links (you should have more than one) need to be as "clear" as possible. If possible, like a dark fiber. Notice that the HA traffic uses a non-standard ethernet frame format which may collide with Cisco Nexus internal usage. This is documented in the Handbook, HA chapter.
When setting this up, is emerged that setting up the external WAN access was more complicated than setting up the FGT cluster. The ISP set up Cisco routers in a VRRP cluster, moving the (one and only) external WAN address to the DR site in case of a failure. The problem was that there was no easy way how the FGTs were notified of a failure. We set it up to switch over manually, but we could have configured remote link monitoring, or the routers could have signalled a failover by dropping the internal link (which the ISP refused to do).
I've done this before, across a big city. No problem.
The main thing is that the HA links (you should have more than one) need to be as "clear" as possible. If possible, like a dark fiber. Notice that the HA traffic uses a non-standard ethernet frame format which may collide with Cisco Nexus internal usage. This is documented in the Handbook, HA chapter.
When setting this up, is emerged that setting up the external WAN access was more complicated than setting up the FGT cluster. The ISP set up Cisco routers in a VRRP cluster, moving the (one and only) external WAN address to the DR site in case of a failure. The problem was that there was no easy way how the FGTs were notified of a failure. We set it up to switch over manually, but we could have configured remote link monitoring, or the routers could have signalled a failover by dropping the internal link (which the ISP refused to do).
thanks, ede_pfau.
For us, we have 2 different ISP for internet access. I am worried about the routing. How both FGT will remain in the cluster using Datalink which will have a different IP range than my internal network.
Dears
I have the same scenario, any updates?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1720 | |
1093 | |
752 | |
447 | |
234 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.