Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
magarm
Visitor

HA setup of fortiauthenticator in 3 sites

I have 3 sites and 6 FAC vms  , 2 fac in HA(active-passive)  in each site is deployed.  one site will be primary and other two will be secondary. can we syn config of primary site with other two site in this setup?

3 REPLIES 3
AEK
SuperUser
SuperUser

I think you need to configure them all as active-active Geo cluster, with a load balancer in which you just configure the LB rule you need.

AEK
AEK
magarm

can i make HA(active-passive) cluster as a loadbalancer?

Debbie_FTNT

Hey magarm,

in a load-balancing FortiAuthenticator cluster you can have an active-passive cluster as primary, but the actual load-balancing nodes must be standalone FortiAuthenticators, not active-passive pairs.

You can have up to ten load-balancing nodes linked to the same primary, and the primary can be an active-passive pair, so you could in theory have two separate load-balancing nodes at each site.

Please note there is no failover or promotion mechanism in a load-balancing cluster, and while most configuration can be synced, not all of it will be.

 

A bit of info on load-balancing setups: https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-How-to-configure-FortiAuthenticat... 

 

Cheers,

Debbie

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors