Does anyone have MS NLB configured with multicast working on Fortinet gear in routed mode? We have an HA pair (active/passive) of 1801F firewalls with a pair of 3032E switches attached via Fortilink. The Microsoft services we are trying to configure for NLB is an RDS farm that will be accessed through RDGateway. We added a static ARP entry with the cluster IP and multicast MAC, but it appears the Fortigate is dropping the traffic from the Gateway server to the cluster IP.
I opened a ticket with support asking for assistance and this is the reply I got. So disappointed in Fortinet.
"Please note that planning, designing and deploying Fortinet network solutions is out of the scope of Fortinet Technical Support. If you feel that you need help with that I would recommend you to contact your local Fortinet representative in order to get Partner provided or Fortinet provided Professional Services. See the details in the document below:"
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello
Sometimes TAC support may not help if the issue is related to design or integration.
In your case the issue seems not related to a bug, but is probably due to design, integration or configuration.
Check the below first, I think it may help.
https://docs.fortinet.com/document/fortigate/7.4.2/administration-guide/968606
My SE more or less told me the same thing, I asked for a design guide (Cookbook) rather than stating how we already tried setting it up and it didn't work.
I appreciate the link you sent, do you have MS NLB working in your environment?
The link to the guide you sent is for multicast forwarding, which we're not doing, we need multicast routing.
The section for multicast routing and PIM support in the guide indicates a multicast policy needs to be created, however, when trying to create this policy, the destination appears to only allow multicast IP blocks. The catch with MS NLB is, it uses a multicast MAC but a unicast IP, so the few Fortinet guides I have found don't seem to cover this.
I realize my multicast knowledge is rather limited, so perhaps I not connecting all the dots to make it work, which is why I am reaching out to the community for assistance.
I think it is a good idea to check first if your target design is supported by MS. If so then you will probably find in MS docs how such design is implemented.
We had this working fine when we were on Cisco ASA with Dell Force 10 switches, so I know the target design is solid. MS has a great article on the setup with links to guides published by the major network providers (Cisco, Juniper, HPE, Dell, Huawei, D-Link, Avaya, and VMWare) on how to configure their gear to support MS NLB.
I ask again, do you have MS NLB working in your envir
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1705 | |
1093 | |
752 | |
446 | |
230 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.