Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
victorcreed
New Contributor III

HA heartbeat using fibre SFP ports

Hello

 

For HA heartbeat Fortinet documentation advises to use copper ports. E.g. dmz and wan2

 

http://docs-legacy.fortinet.com/cb/html/index.html#page/FOS_Cookbook/Install_advanced/cb_install-ha....

 

We only have fibre patch panels between the racks where the firewalls will be placed. We have Fortigates 2 x 600Cs

 

Can anybody think on any reason why I should not use the fibre SFP ports for HA heartbeats?

 

 

Thanks,

 

 

3 Solutions
discoscott
New Contributor III

One concern I would have is that its likely the fibre run between your firewalls are through a single 6-12+ core fibre run. Fortinet suggest using 2 ports for HA heartbeat for redundancy - if the 6-12+ core fibre run is cut you will lose both heartbeats.

 

My preference would be to put both HA firewalls within 5-10 metres of each other and use the fibre to patch the other buildings network into the HA Pair.

 

 

View solution in original post

emnoc
Esteemed Contributor III

That's doable and no reason why you can't us a fiber port+transceiver. Some time this is the only mean if  the cluster exceed the distance of copper

 

e.g

 

FW1 and FW2 over 300m away or on different floor or different buildings

 

PCNSE 

NSE 

StrongSwan  

View solution in original post

PCNSE NSE StrongSwan
vjoshi_FTNT
Staff
Staff

Hello,

 

I have seen few setups using the fiber ports for the HA heartbeat interfaces without any issues

 

I don't see any specific reason why they should not be and also the document doesn't say anything about it. By saying the a regular ethernet cable, it covers all the units (including the low end models), may be, that is the reason the document points the regular ethernet cable

View solution in original post

4 REPLIES 4
discoscott
New Contributor III

One concern I would have is that its likely the fibre run between your firewalls are through a single 6-12+ core fibre run. Fortinet suggest using 2 ports for HA heartbeat for redundancy - if the 6-12+ core fibre run is cut you will lose both heartbeats.

 

My preference would be to put both HA firewalls within 5-10 metres of each other and use the fibre to patch the other buildings network into the HA Pair.

 

 

emnoc
Esteemed Contributor III

That's doable and no reason why you can't us a fiber port+transceiver. Some time this is the only mean if  the cluster exceed the distance of copper

 

e.g

 

FW1 and FW2 over 300m away or on different floor or different buildings

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
vjoshi_FTNT
Staff
Staff

Hello,

 

I have seen few setups using the fiber ports for the HA heartbeat interfaces without any issues

 

I don't see any specific reason why they should not be and also the document doesn't say anything about it. By saying the a regular ethernet cable, it covers all the units (including the low end models), may be, that is the reason the document points the regular ethernet cable

victorcreed

Thank you all, indeed it worked without issues.

Labels
Top Kudoed Authors