Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
magarm
New Contributor II

Load-balancer mode deployment failover

In Load-balancer mode deployment, what happens if primary fac goes down? for an example , I have cluster(A-P) as a primary at HQ and load-balancer at two different geo location.

what happens if my primary HQ is down? can load-balancer take over authentication function.

if so which will be active.

 

 

1 Solution
AEK
SuperUser
SuperUser

There is no automated failover between them, and devices utilizing the FortiAuthenticators will need to switch to a different IP address to address a different node, as if switching to a completely independent device.

Ref:  https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-How-to-configure-FortiAuthenticat...

 

E.g.: if you are using RADIUS authentication, on each device you configure the first FAC as primary and the second as secondary.

You can also achieve the fail-over via a separate load-balancer (I mean LB like FortiADC). In this case the devices send the authentication request to the LB and the LB knows which FAC is up and which one is down.

AEK

View solution in original post

AEK
2 REPLIES 2
AEK
SuperUser
SuperUser

There is no automated failover between them, and devices utilizing the FortiAuthenticators will need to switch to a different IP address to address a different node, as if switching to a completely independent device.

Ref:  https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-How-to-configure-FortiAuthenticat...

 

E.g.: if you are using RADIUS authentication, on each device you configure the first FAC as primary and the second as secondary.

You can also achieve the fail-over via a separate load-balancer (I mean LB like FortiADC). In this case the devices send the authentication request to the LB and the LB knows which FAC is up and which one is down.

AEK
AEK
magarm
New Contributor II

Can the load-balancer fortiauthenticator at Branch perform authentication (MFA, SSO) of local application. or it forwards the traffic to primary cluster?

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors