Hello
I have 4 FGT 7.0.12 of the same model in FGSP configuration (no HA), handling asymmetric traffic.
For non-UTM sessions, when testing failover (FGT reboot) all works fine, the sessions keep working when the node fails-over and fails-back.
However for UTM sessions the fail-over doesn't work when we have 4 nodes.
If the FGT handling the UTM session is rebooted, the session hangs until the node boots up, then it handles back its UTM session.
When I remove 2 FGT from my network and redo the test with only 2 FGT the fail-over works just fine.
In summary:
Any idea?
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Generally speaking asymmentric traffic is not recommended and we do not support such setups.
UTM Inspection on asymmetric traffic in FGSP is not supported for over 2 units. Support was introduced in 6.4 (587694), but only for 2 units.
Logically thinking, for a session that is inspected, the FG needs to intercept the handshake, the request, the session start. For asymmetric traffic, anything after a failover or path change is just regular traffic.
https://community.fortinet.com/t5/FortiGate/Technical-Note-How-the-FortiGate-behaves-when-asymmetric...
" No security inspection will be performed:"
Even if this behavior is somehow supported/implemented - it may be best to check with your local Fortinet System Engineer for testing/advice.
Generally speaking asymmentric traffic is not recommended and we do not support such setups.
UTM Inspection on asymmetric traffic in FGSP is not supported for over 2 units. Support was introduced in 6.4 (587694), but only for 2 units.
Logically thinking, for a session that is inspected, the FG needs to intercept the handshake, the request, the session start. For asymmetric traffic, anything after a failover or path change is just regular traffic.
https://community.fortinet.com/t5/FortiGate/Technical-Note-How-the-FortiGate-behaves-when-asymmetric...
" No security inspection will be performed:"
Even if this behavior is somehow supported/implemented - it may be best to check with your local Fortinet System Engineer for testing/advice.
Created on 08-30-2023 03:39 AM Edited on 08-30-2023 04:30 AM
Hello Alex
Thanks for the useful info. This explain many things.
I think Fortinet didn't publish much information regarding FGSP.
Also I couldn't find this info regarding 2 FGSP nodes limitation with UTM anywhere on admin guide, release notes, etc...
I'd appreciate if you can help with this.
Hi AEK,
It's not very clear even internally where the limitation comes from.
This is why someone may need to follow up with development on this one.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1641 | |
1069 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.