Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

High availability (Active/Passive) in transparent mode

Hello, I would like to be sure of the behaviour of High availability (Active/Passive) in transparent mode and check potential loops as I can' t find a clear explanation in the documentation : if you have a cluster of 2 Fortigate in transparent mode between 2 switches, with for example : Switch1 - Fortigate Cluster - Switch2 -Port 1 of Fortigate1 and port 1 of Fortigate2 connected to Switch 1 -Port 2 of Fortigate1 and port 2 of Fortigate2 connected to Switch 2 Fortigate is the primary node, is there any risk of Loop between Fortigate1, Switch1, Fortigate2 and switch2 ? Do the Fortigates behaves like a switch ? (with of course the packet inspection) In a cluster Active/Passive in transparent mode, are the interfaces port1 and port2 of the slave unit deactivated so that switch1 sees switch2 only via the primary unit ? If so, all the MAC addresses of the computers connected to the switch2 will be in the MAC address table of the port connected to the Primary Fortigate on the Switch1. Does that mean that if the slave becomes primary, switch1 has to wait until the cache ARP expire to send broadcasts and fills the MAC address table of the port connected to Fortigate2 with MAC addresses of computers connected to Switch2 ? hum....that' s many questions at the same time, I will try to sniff every interfaces and switch ports at some point when I have time but I need answers quickly. Regards,
2 REPLIES 2
Not applicable

For the question of if there is a risk of loop? Yes there is a risk of loop if you run TP cluster between switches. BUT, if you configure the cluster correctly, it should never happen. You could enable HA heart beat on HA link, AND both interfaces connecting to switches. As long as any one of these interface can talk over heart beat, the loop will not happen. Even in A-P mode, all interface are active however just not forwarding packets. So the switch will not see any linkup/down in case of failover happen.
Not applicable

Do you mean : - Port Monitor on port 1 and port 2 - Heartbeat Interface on port 4 and 5 or also port 1 and 2 ? Thanks
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors