My current firewall seems to be able to support using CLI
but I want to do using GUI.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Link monitor is used to remove routes from routing table in case one link (interface) fails.
I don't quite understand your requirements here or what are you trying to accomplish
It is very simple.
Same as Cisco.
IP sla to track 8.8.8.8.
When vrrp fails the IP sla, it decrements the priority.
This is standard setup.
You have given me links for vrrp. But not how to integrate priority decrement and IP sla with vrrp. Just like a Cisco config.
Created on 09-29-2023 11:04 AM Edited on 09-29-2023 11:05 AM
Be aware FGT's VRDST "monitor" is not the same with Cisco's IP SLA as the KB @heng provided the link to is describing. It monitors only kernel routing table to see a match. Never sends out ping to the server IP.
Toshi
If it is such as a serious issue. You should bring it up to the r&d. Not everyone reads this forum.
If it doesn't do active ping how does it check that the link is down?
What is the purpose of link monitoring then?
Then how is it supposed to detect that the link is down without probes?
Created on 09-30-2023 02:33 PM Edited on 09-30-2023 02:34 PM
If the link goes done all routes bound to the link will be removed. That's how VRDST route removal can be detected. A possible issue is if another route that covers the VRDST, such as 0/0, is coming from or bound to another link with a lower precedence, it won't see it as down. There are some options to mitigate that and the link @heng pointed shows one option.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-VRRP-Active-failover-with-VRDST-with-black...
Toshi
Hi,
There are few KBs that described the the usage for the link monitor + VRRP failover. Please take a look, thanks.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-VRRP-Active-failover-with-link-monitor/ta-...
Also there is no set vrrp or config vrrp in my interface mode.
What should i do?
hi,
Can you post your snippet config here with ? when you are under system interface.
Also, what is your FGT model?
Created on 09-29-2023 09:16 PM Edited on 09-29-2023 09:17 PM
I solved it. Wrong type of interface.
I am more concerned with what tochi is saying above.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1712 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.