PCNSE
NSE
StrongSwan
ORIGINAL: emnoc Lastly, if you want the best of approach run 2x interfaces from each FGT to the same switch and then you have link redundancey.To be able to run link redundancy like this, does the FGT have to be in interface mode instead of switch mode? Anything else to do on FGT or switch? Right now I have a site where I have the VLANs trunked to the FGT-60C over a single link. I have lots of extra ports on the Cisco switch. I' m interested in gaining link redundancy if it' s as easy as you begin to suggest.
I have to disagree with edu_pfau analysis to a certain degree. Yes you can interconnect 2 FGT in the fashion that you mention above. FGT01--int1 ==sw1 FGT02--int1 ==sw2 and have sw1/sw2 tied with a lacp etherbundle. This is normal and SOP in most areas. You can also run these FGT in act/act or act/pas mode via. I do that all day long with ASA , pfsense w/carp, Juniper and with Act/pas for FGT for no real reason.Sorry, no, this will not work at all! You' re building loops, with identical traffic origin coming in on one port of the switch and on another as well (the inter-switch link). This cannot work. The first broadcast will cause a broadcast storm. Maybe you can see it from another perspective: the server receives traffic from FGT #1 via switch #1, using the cluster MAC for the int1 interface. Which NIC should the server use to send the reply out? Assume NIC1. Next packet arrives, with the SAME MAC, via NIC2. How does the server keep the L2 traffic apart then? IMHO this discussion is becoming academic. Set it up, make the loop and see for yourself.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1743 | |
1114 | |
760 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.