Hello,
I would like to be sure of the behaviour of High availability (Active/Passive) in transparent mode and check potential loops as I can' t find a clear explanation in the documentation :
if you have a cluster of 2 Fortigate in transparent mode between 2 switches, with for example :
Switch1 - Fortigate Cluster - Switch2
-Port 1 of Fortigate1 and port 1 of Fortigate2 connected to Switch 1
-Port 2 of Fortigate1 and port 2 of Fortigate2 connected to Switch 2
Fortigate is the primary node, is there any risk of Loop between Fortigate1, Switch1, Fortigate2 and switch2 ?
Do the Fortigates behaves like a switch ? (with of course the packet inspection)
In a cluster Active/Passive in transparent mode, are the interfaces port1 and port2 of the slave unit deactivated so that switch1 sees switch2 only via the primary unit ?
If so, all the MAC addresses of the computers connected to the switch2 will be in the MAC address table of the port connected to the Primary Fortigate on the Switch1. Does that mean that if the slave becomes primary, switch1 has to wait until the cache ARP expire to send broadcasts and fills the MAC address table of the port connected to Fortigate2 with MAC addresses of computers connected to Switch2 ?
hum....that' s many questions at the same time, I will try to sniff every interfaces and switch ports at some point when I have time but I need answers quickly.
Regards,