Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
BernhardH
New Contributor

VRRP Internet, HA Fortinets & multi-enclosure HP Virtual Connect

Hello, everyone! After some days of frustration, I am seemingly stuck with my configuration. I have: 2x 310B Fortigates, set up in a HA (active/active - but can also be active/passive if required) cluster 2x c7000 HP blade enclosure with a 1/10F Virtual Connect setup (3.61 firmware) (upcoming, currently faked) VRRP redundant connection to the Internet in our to-be hosting center. I set up the Fortigates to have one aggregate interface, over which several VLANs are routed to the Blade Centers. Also, each Fortigate has a redundant interface for the Internet connection (I suppose I have to change this for the VRRP setup) I was hoping to connect the shared uplink set of the Virtual Connect domain to an aggregate interface on each firewall directly, without using a switch (the Virtual Connect should look like one " server" to the firewall). Originally, I was planning on a meshed solution like this: Internet1a -> Fortigate1 Internet1 Internet1b -> Fortigate2 Internet1 Internet2a -> Fortigate1 Internet2 Internet2b -> Fortigate2 Internet2 SharedULSet: C7000-1 Switch1.1->Fortigate1 UL1 C7000-1 Switch2.1->Fortigate1 UL2 C7000-1 Switch1.2->Fortigate2 UL1 C7000-1 Switch2.2->Fortigate2 UL2 C7000-2 Switch1.3->Fortigate1 UL3 C7000-2 Switch2.3->Fortigate1 UL4 C7000-2 Switch1.4->Fortigate2 UL3 C7000-2 Switch2.4->Fortigate2 UL4 ...but somehow, this was doomed on the Virtual Connect side. There was no aggregation happening, only one link active-linked, the rest active-standby. No Data connection to the blades. OK, I then changed this to 2 different Shared ULSets, as suggested by some guides, and combined the uplinks to only 2 switches: SharedULSet1: C7000-1 Switch1.1->Fortigate1 UL1 C7000-1 Switch1.2->Fortigate1 UL2 C7000-1 Switch1.3->Fortigate1 UL3 C7000-1 Switch1.4->Fortigate1 UL4 SharedULSet2: C7000-2 Switch2.1->Fortigate2 UL1 C7000-2 Switch2.2->Fortigate2 UL2 C7000-2 Switch2.3->Fortigate2 UL3 C7000-2 Switch2.4->Fortigate2 UL4 Better: the LAG groups of the different sets matched now, with 2x4 links active-linked. Still, no connctivity to the blades. If I pull out the cables from one firewall - everything works (imagine my " joy" at getting pings back after 3 days of silence)! Well...no HA firewall solution, which is not OK for production :) So...my question is - is there any chance I can solve this connectivity problem without getting 2 stacked switches to sit in between the firewall and the Virtual Connect? It would be fine for me, if the " non-active" firewall would signal its links as down to the Virtual Connect stack. Regarding the VRRP connection to the Internet Routers - will this work " out of the box" as I planned with 4 connections to 2 core switches (talking VRRP) at the ISP? Cheers, Bernhard
1 REPLY 1
BernhardH
New Contributor

Doesn' t seem to be such a common configuration :\
Labels
Top Kudoed Authors