Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Fabio74
New Contributor

HA (High Availability)

Good morning everyone. Attached is the current sceneHA.png. We have now acquired a second Fortigate 100F. The idea is to configure the two in active-passive HA (High Availability). I have some doubts. 1) Can the WAN be the same? 2) How do I connect and where do I connect the three doors of the second Fortigate? 3) The 3 ports of the first Fortigate are configured as DHCP Servers, will they continue to work?

3 Solutions
srajeswaran
Staff
Staff

srajeswaran_0-1677495461221.png

This is the ideal method and all the functionalities will continue to work as in the current setup.

Regards,
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.

View solution in original post

srajeswaran

Yeah, the same ports from both units need to connect to the same LAN subnets. The LAN segments in diagram shows switches, is that so? If so, you just need to add one port to the connection towards the new FGT unit.

 

Regards,
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.

View solution in original post

srajeswaran

Hi Fabio,

 

Yes, this is correct and expected to work.

Regards,
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.

View solution in original post

9 REPLIES 9
srajeswaran
Staff
Staff

srajeswaran_0-1677495461221.png

This is the ideal method and all the functionalities will continue to work as in the current setup.

Regards,
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
Fabio74

Woww... Great, thanks for the quick reply srajeswaran. Two more little doubts. 1) I don't have a Layer 2 switch, can it still work? 2) I connect ports H1 and H2 equally to each other, right?

srajeswaran

Yeah, the same ports from both units need to connect to the same LAN subnets. The LAN segments in diagram shows switches, is that so? If so, you just need to add one port to the connection towards the new FGT unit.

 

Regards,
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
Fabio74

OK perfect. Sorry but the translator often doesn't work effectively. So I can use a regular 1GB Switch. I entered the new design. Last thing, the 3 LAN ports are currently configured in VLAN Switch. Is that okay?HA.png

srajeswaran

yes, this looks fine. Yes, the VLANs can be configured on the VLAN switch, just need to make sure the FGT ports (from both nodes) are mapped to the corresponding LAN ports.

Regards,
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
Fabio74
New Contributor

I was wrong, actually the scheme should be this, precisely because I don't have a layer2 switchHA.png

srajeswaran

Hi Fabio,

 

Yes, this is correct and expected to work.

Regards,
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
Fabio74

Let's hope so. It's the first time I try something more advanced. Also because I made the company spend a lot of money :) Thank you very much for the technical and moral support :)

srajeswaran

You are welcome. Feel free to post more if you face any issues while implementing. We are here to help.

Regards,
Suraj
- Have you found a solution? Then give your helper a "Kudos" and mark the solution.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors