Hello,
We've got a BGP configuration in the datacenter (see screenshot below) and we have 2 FortiGates (100F).
We want to make the FortiGates highly available. But for both ports we have a /30 subnet so our external IP address is different for both ports.
Is this even possible (to have different IP addresses on both ports and use HA) or should we switch to a different configuration
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi @JesperAP ,
I am not a design expert. When you configure FGCP you have to configure the WAN interface IP on primary unit and it will be automatically sync'd to secondary unit, so primary and secondary units interfaces have the same IPs. On your WAN interface you may enable/assign a secondary IP (using the IP belonging to the secondary BGP subnet /30). Bear in mind that the BGP configuration/peering will only be active on the current primary unit and I am not sure about the performances of that implementation and consequent BGP peering failover.
https://docs.fortinet.com/document/fortigate/6.4.0/ports-and-protocols/564712/fgcp-fortigate-cluster...
It might be worth contacting your SE and ask for a Professional Services consultancy.
Best regards,
Isn't it a option to make a VDOM exception for the WAN interface?
https://docs.fortinet.com/document/fortigate/7.0.5/administration-guide/105611/vdom-exceptions
How do I specify to only have a exception for the WAN interface?
You can not do HA with those two FGTs because this BGP design assumes two independent routers (FGTs) on the customer end.
Toshi
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1721 | |
1098 | |
752 | |
447 | |
234 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.