In Load-balancer mode deployment, what happens if primary fac goes down? for an example , I have cluster(A-P) as a primary at HQ and load-balancer at two different geo location.
what happens if my primary HQ is down? can load-balancer take over authentication function.
if so which will be active.
Solved! Go to Solution.
There is no automated failover between them, and devices utilizing the FortiAuthenticators will need to switch to a different IP address to address a different node, as if switching to a completely independent device.
E.g.: if you are using RADIUS authentication, on each device you configure the first FAC as primary and the second as secondary.
You can also achieve the fail-over via a separate load-balancer (I mean LB like FortiADC). In this case the devices send the authentication request to the LB and the LB knows which FAC is up and which one is down.
There is no automated failover between them, and devices utilizing the FortiAuthenticators will need to switch to a different IP address to address a different node, as if switching to a completely independent device.
E.g.: if you are using RADIUS authentication, on each device you configure the first FAC as primary and the second as secondary.
You can also achieve the fail-over via a separate load-balancer (I mean LB like FortiADC). In this case the devices send the authentication request to the LB and the LB knows which FAC is up and which one is down.
Can the load-balancer fortiauthenticator at Branch perform authentication (MFA, SSO) of local application. or it forwards the traffic to primary cluster?
User | Count |
---|---|
2606 | |
1389 | |
804 | |
664 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.