Hello,
I am going through my first FSSO setup right now and curious about a few things here.
Is it possible to setup the following. I have 2 fortigate 800C' s not in HA (two seperate units dont ask...), and a Primary and Secondary DC
first fortigate
-points to primary DC that has both DC Agent and Collector installed. add reg key as suggested to add the IP of the second DC agent on secondary DC
second fortigate
-points to Secondary DC that has both DC agent and Collector installed. Add reg key to add the IP of the first DC agent on Primary DC
why would I do it this way versus
First Fortigate
-primary FSSO collector IP to Primary DC with DC Agent and Collector installed
-Secondary FSSO Collector IP to Secondary DC with DC Agent and Collector installed
Second Fortigate
-primary FSSO collector IP to Secondary DC with DC Agent and Collector installed
-Secondary FSSO Collector IP to Primary DC with DC Agent and Collector installed
I feel like what i wrote as the second setup option makes more sense. No need for reg keys. I would assume as long as you have the correct password to communicate it wont care who its coming from, or will this cause problems in communication?
My secondary fortigate is not active unless my core switches failover to the secondary switches which uses the secondary fortigate so unless its just pinging it to confirm a connection it shouldnt be doing anything else?
-Phil
IT Security Analyst
-Phil