Hello
For HA heartbeat Fortinet documentation advises to use copper ports. E.g. dmz and wan2
We only have fibre patch panels between the racks where the firewalls will be placed. We have Fortigates 2 x 600Cs
Can anybody think on any reason why I should not use the fibre SFP ports for HA heartbeats?
Thanks,
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
One concern I would have is that its likely the fibre run between your firewalls are through a single 6-12+ core fibre run. Fortinet suggest using 2 ports for HA heartbeat for redundancy - if the 6-12+ core fibre run is cut you will lose both heartbeats.
My preference would be to put both HA firewalls within 5-10 metres of each other and use the fibre to patch the other buildings network into the HA Pair.
That's doable and no reason why you can't us a fiber port+transceiver. Some time this is the only mean if the cluster exceed the distance of copper
e.g
FW1 and FW2 over 300m away or on different floor or different buildings
PCNSE
NSE
StrongSwan
Hello,
I have seen few setups using the fiber ports for the HA heartbeat interfaces without any issues
I don't see any specific reason why they should not be and also the document doesn't say anything about it. By saying the a regular ethernet cable, it covers all the units (including the low end models), may be, that is the reason the document points the regular ethernet cable
One concern I would have is that its likely the fibre run between your firewalls are through a single 6-12+ core fibre run. Fortinet suggest using 2 ports for HA heartbeat for redundancy - if the 6-12+ core fibre run is cut you will lose both heartbeats.
My preference would be to put both HA firewalls within 5-10 metres of each other and use the fibre to patch the other buildings network into the HA Pair.
That's doable and no reason why you can't us a fiber port+transceiver. Some time this is the only mean if the cluster exceed the distance of copper
e.g
FW1 and FW2 over 300m away or on different floor or different buildings
PCNSE
NSE
StrongSwan
Hello,
I have seen few setups using the fiber ports for the HA heartbeat interfaces without any issues
I don't see any specific reason why they should not be and also the document doesn't say anything about it. By saying the a regular ethernet cable, it covers all the units (including the low end models), may be, that is the reason the document points the regular ethernet cable
Thank you all, indeed it worked without issues.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.