Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AEK
SuperUser
SuperUser

ZTNA Georredendancy

Hi ZTNA admins

Regarding EMS georedundancy HA deployment, on each site there is one EMS, one edge FGT, and each has its public IP. The clients are registered with ztna.domain.com pointing to the first site's public IP.

My question is, what is the best way to have a redundant deployment that makes switching ZTNA app gateway as transparent as possible to the user.

My first though is to use FortiADC's GSLB, so the DNS directs to the available ZTNA gateway. However it seems for me an excessive solution for a small problem. So I think that some simpler solutions should exist.

Any idea will be welcome.

AEK
AEK
4 REPLIES 4
Anthony_E
Community Manager
Community Manager

Hello Abdelkrim,

 

I hope you are doing well :)!!!


Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.


Thanks,

Anthony-Fortinet Community Team.
AEK

Hello Anthony

Hope you are doing fine too.

Thanks for your support!

AEK
AEK
Anthony_E
Community Manager
Community Manager

As usual, it is a pleasure if we can help you.

 

I found this answer with our documentations:

 

To achieve a redundant deployment for ZTNA Application Gateway with minimal user disruption, you can consider the following approach:

  1. DNS Configuration:

    • Use a DNS service that supports failover. Configure the DNS to point ztna.domain.com to the primary site's public IP.
    • Set a low TTL (Time to Live) for the DNS record to ensure quick propagation of changes.
  2. FortiADC GSLB:

    • While FortiADC's GSLB might seem excessive, it provides a robust solution for automatic failover and load balancing.
    • GSLB can dynamically direct traffic to the available ZTNA gateway based on health checks and proximity, ensuring users are routed to the best available site.
  3. FortiGate Configuration:

    • Ensure both FortiGates are configured to handle ZTNA traffic and have the necessary policies in place.
    • Use FortiGate's built-in capabilities to monitor the health of the ZTNA gateway and switch traffic if the primary site becomes unavailable.
  4. Monitoring and Alerts:

    • Implement monitoring to detect failures or performance issues with the primary ZTNA gateway.
    • Set up alerts to notify administrators of any issues, allowing for quick manual intervention if needed.
  5. Testing and Validation:

    • Regularly test the failover process to ensure that it works as expected and that users experience minimal disruption.

By using a combination of DNS failover and FortiGate's capabilities, you can achieve a redundant deployment that is both cost-effective and efficient for a smaller setup.

 

Is that helping?

 

Regards,

Anthony-Fortinet Community Team.
AEK

Thanks for your feedback, Anthony.

This is indeed one of the possible solutions.

Any other suggestions are welcome.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors