Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Mustan_Ali
New Contributor

HA/Distributed Clustering Across Two Different Location

I have two FortiGate 200D in HA mode currently and need to transfer one of them to the DR location. DR Site IP range and HO IP ranges are the same. Core Switch with different VLAN is having a gateway set to firewall LAN IP.

 

Is it Possible to have an HA configured using Datalink connectivity between 2 different geographic locations?

Do any other Changes are required on the Core switch?

1 Solution
ede_pfau
SuperUser
SuperUser

I've done this before, across a big city. No problem.

 

The main thing is that the HA links (you should have more than one) need to be as "clear" as possible. If possible, like a dark fiber. Notice that the HA traffic uses a non-standard ethernet frame format which may collide with Cisco Nexus internal usage. This is documented in the Handbook, HA chapter.

 

When setting this up, is emerged that setting up the external WAN access was more complicated than setting up the FGT cluster. The ISP set up Cisco routers in a VRRP cluster, moving the (one and only) external WAN address to the DR site in case of a failure. The problem was that there was no easy way how the FGTs were notified of a failure. We set it up to switch over manually, but we could have configured remote link monitoring, or the routers could have signalled a failover by dropping the internal link (which the ISP refused to do).


Ede

"Kernel panic: Aiee, killing interrupt handler!"

View solution in original post

Ede"Kernel panic: Aiee, killing interrupt handler!"
2 REPLIES 2
ede_pfau
SuperUser
SuperUser

I've done this before, across a big city. No problem.

 

The main thing is that the HA links (you should have more than one) need to be as "clear" as possible. If possible, like a dark fiber. Notice that the HA traffic uses a non-standard ethernet frame format which may collide with Cisco Nexus internal usage. This is documented in the Handbook, HA chapter.

 

When setting this up, is emerged that setting up the external WAN access was more complicated than setting up the FGT cluster. The ISP set up Cisco routers in a VRRP cluster, moving the (one and only) external WAN address to the DR site in case of a failure. The problem was that there was no easy way how the FGTs were notified of a failure. We set it up to switch over manually, but we could have configured remote link monitoring, or the routers could have signalled a failover by dropping the internal link (which the ISP refused to do).


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Mustan_Ali

thanks, ede_pfau.

For us, we have 2 different ISP for internet access. I am worried about the routing. How both FGT will remain in the cluster using Datalink which will have a different IP range than my internal network.

Labels
Top Kudoed Authors