I am using the Active/Passive template from https://github.com/fortinet/azure-templates/tree/main/FortiGate/Active-Passive-ELB-ILB.
The diagram below illustrates the setup which I have in three different Azure regions. The primary region is setup as the fabric root but the other fortigate clusters cannot connect to the root via the internal load balancer (.68 in the diagram below). If I use .69 this works until the B firewall becomes active and then I need to manually change this to .70 on the downstream Fortigates. How can I setup downstream fortigates to use the ILB address (.68).
I
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Created on 02-25-2022 10:26 AM
Hello @j_hodges ,
Thanks for posting to Fortinet Community Forums. We appreciate your patience.
We will soon have someone helping you with this query.
Hello,
Thank you for your question. I am not entirely sure what am I looking at. If I understand correctly, FortiGates with IPs .69 and .70 are the primary and secondary devices of one cluster, correct? If this is correct, what kind of interfaces have .69 and .70 IPs? Normal LAN interfaces or HA out-of-band management interface? Because if these interfaces are normal LAN interfaces, only interface on primary device is active and can manage fabric.
Another question, this load balancer is Azure load-balancer that is load-balancing traffic from .68 IP address to .69 and .70. Is this load-balancer also doing DNAT? Maybe I am missing something, but I don't understand the need for load-balancer as cluster is working in Active-passive.
Thanks for your response @akristof. As I mentioned this topology is supplied by Fortinet at https://github.com/fortinet/azure-templates/tree/main/FortiGate/Active-Passive-ELB-ILB. It's also documented at https://docs.fortinet.com/document/fortigate-public-cloud/7.0.0/azure-administration-guide/983245/ha....
To answer your question, .69 and .70 are internal (LAN) interfaces. The Azure load balancer is required in this setup as described at https://docs.microsoft.com/en-us/azure/architecture/reference-architectures/dmz/nva-ha. As a summary this is how Azure implements Active/Passive for Network Virtual Appliances (NVAs).
In theory I should be able to use .68 as the fabric connection target in downstream Fortigates. The Azure Load Balancer will simply send it to the active Fortigate. For reason I can't explain the Fortigate ignores the connection.
Hi,
Thanks for reply. In that case I will let anyone else reply who has more experience with Azure deployments.
Adrian,
Is anyone with experience in these deployments able to elaborate on security fabric connectivity to Azure HA firewalls or is this something that is still unknown? I know this is an old post but I can't really find any other information out there about this.
Blake
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1696 | |
1091 | |
752 | |
446 | |
228 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.