Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
BusinessUser
Contributor

Is it possible to configure VRRP in fortigate using GUI?

My current firewall seems to be able to support using CLI 

but I want to do using GUI.

25 REPLIES 25
xshkurti

Link monitor is used to remove routes from routing table in case one link (interface) fails.
I don't quite understand your requirements here or what are you trying to accomplish

BusinessUser

It is very simple. 

Same as Cisco. 

IP sla to track 8.8.8.8.

When vrrp fails the IP sla, it decrements the priority.

This is standard setup.

You have given me links for vrrp. But not how to integrate priority decrement and IP sla with vrrp. Just like a Cisco config. 

Toshi_Esumi

Be aware FGT's VRDST "monitor" is not the same with Cisco's IP SLA as the KB @heng provided the link to is describing. It monitors only kernel routing table to see a match. Never sends out ping to the server IP.

 

Toshi

BusinessUser

If it is such as a serious issue. You should bring it up to the r&d. Not everyone reads this forum.

 

If it doesn't do active ping how does it check that the link is down? 

 

What is the purpose of link monitoring then?

BusinessUser

Then how is it supposed to detect that the link is down without probes? 

Toshi_Esumi

If the link goes done all routes bound to the link will be removed. That's how VRDST route removal can be detected. A possible issue is if another route that covers the VRDST, such as 0/0, is coming from or bound to another link with a lower precedence, it won't see it as down. There are some options to mitigate that and the link @heng pointed shows one option.  
https://community.fortinet.com/t5/FortiGate/Technical-Tip-VRRP-Active-failover-with-VRDST-with-black...

Toshi

BusinessUser
Contributor

Also there is no set vrrp or config vrrp in my interface mode.

What should i do?

heng

hi, 

 

Can you post your snippet config here with ? when you are under system interface. 

Also, what is your FGT model?  

NSE8
BusinessUser

I solved it. Wrong type of interface.

I am more concerned with what tochi is saying above.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors