We have 2 Application servers that have some applications connect locally to pg-pool on the same server. 2 Postgresql Databases servers, stacking switch between AP servers to firewall and stacking switch between firewall to DB servers. When we updated the firewall firmware, we have about 1 minute downtime for fail-over process between the firewall devices. After that, the pg-pool connection to database server disconnected once and re-connected after that. But the application still timeout and disconnect. I would like to know if there is a way to update firewall firmware on 1 firewall without network disconnection? Thank you!
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
If not enabled, the down period should start at the point b) in my previous comment. Then go down again (if came back up once) at the point c).
Toshi
Yes. That is the case of my problem. I will enable session-pickup and try it again. Thank you Mr.Toshi.
If you have many sessions (very busy) on the FGTs, you might still experience some down time even with session-pickup enabled at the point c). Because the swapping at point c) is almost immediate when the original primary came back up after the upgrade is done, without any time to sync the sessions with the original secondary/temporay primary.
At the point b), the original primary waits a while until all possible secondary units reply to it for the completion of secondary upgrades, which gives some time for the secondary to sync the sessions with the primary before the swap.
Toshi
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1717 | |
1093 | |
752 | |
447 | |
234 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.