Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
akabarasif
New Contributor III

How to Config redundant ISP with HA without having switch?

HI,

we have 2 ISPs directly connected. it is P2P link one is L3-P2P another is L2-P2P, 1 link is connected to primary firewall and 2nd is connected to secondary firewall, both firewall has active/active HA enabled. how can i utilised both ISPs 50/50%. Stacked core switch is connected to both firewall.

3 REPLIES 3
lobstercreed
Valued Contributor

Can you not buy a couple of tiny cheap unmanaged switches?  If you're going to do HA you need to do it right which means you're going to need a switch.

 

If you don't want to buy anything, create two VLANs for this purpose on your core switch.  It does consume 6 total ports, but that's what we have done.  VLAN 3333 is ISP1 and has 1 port out to the ISP equipment, 1 port to primary firewall, 1 port to secondary firewall.  Then VLAN 3334 is ISP2 and has 1 port out to the ISP equipment, 1 port to primary firewall, 1 port to secondary firewall.

akabarasif

lobstercreed wrote:

Can you not buy a couple of tiny cheap unmanaged switches?  If you're going to do HA you need to do it right which means you're going to need a switch.

 

If you don't want to buy anything, create two VLANs for this purpose on your core switch.  It does consume 6 total ports, but that's what we have done.  VLAN 3333 is ISP1 and has 1 port out to the ISP equipment, 1 port to primary firewall, 1 port to secondary firewall.  Then VLAN 3334 is ISP2 and has 1 port out to the ISP equipment, 1 port to primary firewall, 1 port to secondary firewall.

Hi,

actually we are using same firewall instead of both firewall without HA for a time being. we config the SD-wan with ipsec tunnel but link is not fully utilising. each link has 2 Mbps speed. both side we config sd-wan from HQ-branch and branch-HQ. but i see more packet loss in 1 link. could you please tell me how to solve this issue ?

 

harmesh88
New Contributor

As you mentioned in post that you dont have switch for ISP Connectivity 

 

You should connect both ISP in Primary Firewall and then you can use ISP load sharing Method and use both ISP 

 

Once your primary Firewall will goes down you should manually connect both link to secondary Firewall

 

If you dont want manual fail over and need auto fail over - You should have one L2 switch other wise you can use port from your core switch by making one isolated VLAN .

 

And you can achieve it 

 

Regards,

Harmesh Yadav

CCNP CCSE

 

 

Labels
Top Kudoed Authors