Two Cisco firewall in active passive mode. Suppose I put two Fortigate firewall ha pair one on each side inline behind the Cisco firewall for monitoring. How do I detect the Cisco firewall switched it's active one and therefore will switch to the correct active side on the Fortigate?
To answer your questions:
1. Link monitor will not cause HA to failover. Link monitor is only for Routing process
Link monitoring and HA failover time | FortiGate / FortiOS 7.0.0 | Fortinet Document Library
2. Active-Active HA presumes that Cisco ASA is also Active-Active, thus sending and receiving traffic on both devices simultanously
3. Even after using FortiGate in Standalone, you will need a load-balancer in front of them, so that end-users will use only the device that can route traffic at specific time.
What you can do in this case, is to cross-connect fortigate and cisco.
So the design will allow you to configure fortigate ha in active-passive mode.
At this point, with link-monitor you can route traffic to first cisco or to second cisco device based on the functionality. If first cisco device is not forwarding traffic, the sessions will be forwarded to second cisco because of link monitoring.But as stated before, you need to cross-connect devices.
Each fortigate connected to both cisco devices. Otherwise you can use a Switch between cisco and fortigate. Cisco will use its virtual (HA) mac and FortiGate will forward traffic to that mac address, no matter which cisco device is active. The same way cisco will send traffic to FortiGate HA virtual mac address, no metter which one is active at a given time.
Sorry I forgot to mention how do we do this using virtual wire pair? We plan to do deep packet inspection with policy filtered by ips on some traffic using the virtual wire pair. How would you cross connect fortigate and cisco in this case?
In this case, you do not need a cross-connect; you need a switch between Cisco and Fortigate so that each Fortigate can connect to each Cisco through the same port.
Something like the design below. Of course you can use stack for switches, or other technologies to avoid single point of failure, or you can also use VLANs for wire pairs so you can use that port for other VLANs as well for full utilization.
Thank you for that explanation. Is it possible to do this without using a switch but with cross connect that you mentioned? How would you cable and configure it?
User | Count |
---|---|
2593 | |
1382 | |
800 | |
659 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.