Hi, I am trying to implement 2 Firewall in HA with 2 ISP.Please guide me the best solution in which i can achieve HA along with 2 ISPs.
I want to achieve below attached solution.Please guide me the whole procedure along with the requirements that i shall be needing in order to implement this solution. Shall i be needing load balance for WAN or should i achieve this with out load balance?
Your professional suggestions & solution is needed in this case.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Configure SD-WAN, that's how you do load balancing with Fortigate:
For HA, well, you implement HA as per the below article depending on active/active or active/passive....
https://docs.fortinet.com...1720/high-availability
For the 2 x internal interfaces per firewall we configured BGP routing between the Forti HA cluster and a Cisco 9500X cluster as per your image
I don't think you should need to load balance but you could if you wanted to. I usually think, what matters more, performance or availability. With load balancing you can lose HA if both firewalls are at 60% load and one fails. The other member won't be able to take the full load. With HA one firewall is always doing nothing but should always be able to handle the load when you fail-over. Load balacing makes more sense once you have 3 firewalls IMO.
I believe you often want to have your ISP's connect to a switch which then connects to your firewalls. We use our Core Switches to handle the external connections from our ISP's into our firewalls as well as the internal connections from the firewalls to the rest of our LAN. If you can buy dedicated external switches to go between your ISP's and firewalls that's preferred.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1536 | |
1029 | |
749 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.