Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
SaeedAbdelHalim
New Contributor II

I have 2 fortigate with HA A-P need to connect with 2 Cisco Layer 3 switch

core switch working as layer 3 routing per vlans 

and the two fortigate working as HA A-P 

i need two know how the connection works 

the design also , if there more the idea please need to know all possible solutions and if there any topology diagram the clarify the solution 

9 REPLIES 9
sjoshi
Staff
Staff

Hi,

 

You need to setup LACP between the FGT and the cisco Switches

Refer:-

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Connecting-HA-FortiGates-to-Cisco-Nexus-sw...

Let us know if this helps.
Salon Raj Joshi
SaeedAbdelHalim

it`s not nexus , it`s CAT switch , and  it`s layer 3 all the routing vlan done one it 

 

DPadula
Staff
Staff

Hi Saeed.
Are those 2 cisco switches connected to each other as a stack or independents?
If the Cisco switches are setup as stack, you can use MCLAG instead

Regards

DPadula

 

 

SaeedAbdelHalim

no it`s not stacked

Toshi_Esumi
SuperUser
SuperUser

If the switches are stacked, you just need to have two connections (each could be LAG/Port-channel for switch side redundancy) to both unit, then span the same VLANs to both. Remember, in A-P HA only one unit is active. Then it would simply fail-over from one unit to another when an HA event happens.

Toshi

SaeedAbdelHalim
New Contributor II

dear i all vlan on core switch not fortigate 

Toshi_Esumi

If they're not stacked, and no VLANs are coming to the FGTs, it's simple.
If those two switches are cascaded, you need to connect from the root switch to both FGTs on the same broadcast domain. If those are "parallel" each need to connect both FGTs with separate subnets because those switches are independent L3 routers.
It's up to L3 design on the L2/L3 router/switch side.

Toshi

SaeedAbdelHalim
New Contributor II

cloud you please provide my with design 

Toshi_Esumi

What I implied with my previous message was without knowing your L3 design between those two L3 switch/routers with the FGT(in HA), and some key L3 topology on the Cisco side, it's impossible to design it.

Toshi

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors