Hello fellow Fortinet people. We have a new Fortigate Cluster (AP) with VDOMs enabled (our first Cluster with VDOM config). Now of course we want to monitore both firewalls seperately. Until now we always used the IP addresses of the dedicated management interfaces. However I just learned the following two limitations of Fortigates:
«To get SNMP working with VDOM enabled: Make sure that the interface where the SNMP collector connects to is part of the management VDOM.»
«Note: Dedicated management ports on a HA Cluster will not be part of any VDOM.»
Now from my understanding this means we cannot use the dedicated management interfaces (which are excluded from the HA). Does anyone of you has the same config and if yes, how do you monitor both firewall seperate?
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello,
Thank you for reaching out. If you want to monitor the secondary member of the cluster I believe you will need ha direct and reserving management port. I recommend checking out the article link below for recommendations:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Adding-Secondary-SNMP-server-on-FortiGate-...
Thank you,
Ahmed Saleh
Hello,
Thank you for reaching out. If you want to monitor the secondary member of the cluster I believe you will need ha direct and reserving management port. I recommend checking out the article link below for recommendations:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Adding-Secondary-SNMP-server-on-FortiGate-...
Thank you,
Ahmed Saleh
Yeah we had to enable the HA-Direct option to fully use all services.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1732 | |
1106 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.