Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
asingh07
New Contributor

VRRP ISSUE

I am having problem with VRRP configuration between two fortigate firewall. if i ping towards VIP in vrrp from another vlan and it sends toward bakup interface of vrrp then I dont see response coming back. Anyone aware of this issue and how to rectify this.

13 REPLIES 13
AEK

With network routers this works without issue but when comming to firewalls the rule has changed.

I think one of the following can be a solution.

  • FGSP (session synchronization)
  • Asymmetric routing (should work but not recommended for security)
  • Change your design if possible
AEK
AEK
Toshi_Esumi

It's depending on your objectives with the two FGT devices. If you're looking for hardware redundancy including those all interfaces, active-passive HA (FGCP as @AEK suggests) would be the first and easiest option. You need to change your network/switching design to have all connections to go into both FGTs using switches though.

Toshi

AEK

I think you mean FGCP while I mean FGSP.

AEK
AEK
Toshi_Esumi

@AEKsorry. You're right. I corrected my post. My brain seems to be still in vacation mode.

 

Toshi

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors