Hello, I would know if it is possible to select which kind of traffic/protocol to enable in Session Pickup when configuring the HA. A client asked me for this and I think it is not possible but I just want to be sure. Thank you in advance.
Hi,
Please check the below options in CLI under 'config system ha'
set session-pickup {enable | disable}
##If you enable session pickup the subordinate units maintain session tables that match the primary unit session table, indicates for TCP sessions, and
set session-pickupconnectionless {enable | disable}
##Used for connectionless (UDP and ICMP) sessions
This may have less advantages than you might expect.
For instance, internet-bound traffic will usually be NATted; after a failover the NAT port changes.
With stateless protocols like UDP or ICMP you might find the packet loss tolerable. For incoming streams (like video, audio) session-pickup should make a difference: incoming traffic in the reply direction (e.g. a video stream from the internet) will not be allowed in after a failover without session pickup until the connection is reinitiated.
User | Count |
---|---|
2561 | |
1357 | |
796 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.