Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
BinhDien
New Contributor

VDOM partitioning not work

Hi everyone 

 

I have two firewalls 201G model version 7.4.6, when i configure vdom partitioning with separate two cluster root and rnd. Root is primary in cluster 1 and rnd is primary in cluster 2, but rnd didn't work. I show HA configured, which is no problem; status and role are correct. When i connect the wan port to rnd primay (cluster 2), the port status is down and pppoe is not up, but when i connect the same port on cluster 1, it's up, but pppoe status is installing. Does anybody meet that case, and how can i fix that

 

Thanks for your help

8 REPLIES 8
funkylicious
SuperUser
SuperUser

hi,

if im not mistaken, you would require to have both FGT connected identically to downstream ( to provide redundacy in case of failover among other ) and then you assign the interface to the VDOM/device that you want to handle the traffic.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Configuring-HA-virtual-cluster-with-VDOM/t... 

"jack of all trades, master of none"
"jack of all trades, master of none"
BinhDien

Yes, I also follow that document when I configure, but the vdom in cluster 2 does not work, and the port status is down as I said above.

 

Now, I moved two VDOMs to make them active on the primary firewall. It's working normally. 

funkylicious

i would suggest not connecting any device directly in a FGT, especially when you have a cluster.

instead try connecting those devices in a L2 device (preferably) each in it's own VLAN and then connect the FGTs to the same L2/switch.

"jack of all trades, master of none"
"jack of all trades, master of none"
BinhDien

Thanks for your suggestion, but I wonder why I follow the guide and the status shows correctly. Where was I wrong in this case? And what do I need to check, because the solution " I moved two VDOMs to make them active on the primary firewall. It's working normally." is temporary. Can you give me more suggestion?

funkylicious

try assigning the port that you are connecting on FGT B which is the PRI vcluster for rnd and SEC for root, to rnd VDOM and see if it works.

"jack of all trades, master of none"
"jack of all trades, master of none"
BinhDien

I also tried yesterday. When I connect with the solution you said above, the port status is up, but pppoe status is "installing" forever. However, if I assign a static IP via an internet leased line, it works well. Do you think the cause is fortigate firmware?

funkylicious

have a read at this article as per the pppoe problem, starting with the HA group id, https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Troubleshooting-PPPoE-connection-fai... 

"jack of all trades, master of none"
"jack of all trades, master of none"
BinhDien

Thanks, I use group ID 100 for HA. When I tested yesterday, I didn't see "PADO" response, although I connected both ports on the primary and secondary. I think it has a problem when rnd primary on pppoe process due to wrong forward pppoe packets. Instead of forward to rnd primary node it forward to rnd secondary note. it due to "installing" status. I aslo test pppoe on my laptop, it works.

 

 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors