Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
deepak_verma
New Contributor

HA setup

Hi  ,

 

I have 2 firewalls and trying to setup HA configuration.

 

location A --  Firewall A.

 

location B --  Firewall B .

 

As per requirement , I need to setupHA config between firewall A and Firewall B .

 

Any recommended configuration for such type of setup ..

 

Thanks ..

 

 

5 REPLIES 5
ede_pfau
SuperUser
SuperUser

Just configure HA (a/p or a/a) following the chapter in the FortiOS Handbook. Provide a 'clear' connection to the remote location and connect the HA ports through it. I've done that before.

 

A note: better this line doesn't use Cisco Nexus switches. The ethertype used by the Fortinet HA protocol is different from the standard ethernet, and it is used on Nexus switches internally.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
deepak_verma

Hi Ede ,

 

Thanks for your reply .

 

So just wanted to confirm for HA port , please correct me if I am wrong here ..

 

We just need to tag one vlan to HA ports ---  and allow it through upstream router and need to do similar at other end as well .. right ?

 

Thanks ..

aagrafi

I think you cannot use a VLAN for HA ( at least I tried it with 5.4 and it didn't gave me an option for that).

 

ede_pfau

You cannot use a VLAN for HA as it uses a non-standard ethertype. The line should be layer 2 to allow this.
Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
aagrafi
Contributor II

Hi,

You can find a lot of HA examples in the cookbook (http://cookbook.fortinet.com/?s=high+availability&cat=0). I understand that the two FGs are remote to each other. So, what type the HA links will be? Consider thet these links should be low latency, low packet loss (ideally layer 1 links).

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors