Hello all,
I have a question regarding a design like this.
Suppose CheckPoint A is the Master unit for its cluster, while Forgate A and B are in Active-Active HA.
Fortigate A or B comes with one virtual wire and the VW1 is connected between the Checkpoint and Core switch.
No switch is between Fortigate and Checkpoint.
I wonder if Fortigate B receives traffic from a user, can the user stillbe able to use CheckPoint A to access to the internet?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
Is there any connection between FGTB and checkpoint A or FGTB is only connected to checkpoint B?
Also in checkpoint is it working as Active-Passive mode?
No connection between FGTB and checkpoint A . Only A to A and B to .
Checkpoint is it working as Active-Active - Clueter mode.
Hi Potato
I don't think it will work like that, because the FG Master may not see the CheckPoint Master.
Even in AA-HA, FG master is the one who receives the incoming traffic, so you need a switch between the two firewall clusters.
I will also try your advice. Thank you.
This article describes an example of a simple TCP 3-way-handshake in HA Active-Active cluster where packet distribution between Master and Slave FortiGate occurs.
Refer:-
https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGate-HA-A-A-cluster-3-way-TCP-handsha...
So, what if got drop on Step 3 ?
3) SYN is forwarded from internal interface to External Interface to the external switch connected to the Server
Will the Master FG1 try to resend SYN forward to the Server?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1733 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.