Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
DirkDuesentrieb
New Contributor

server load balancing finally works since FOS 6.4

Hi,
the Fortigate has the vip type "server-load-balance" for a while and some features eg https offloading and cookie persitence looked promising, but there was a bug in the cookie handling that spoiled it all.

Since FOS 6.4 this is fixed and we use this simple slb for a while without issues. So if you think about replacing a fully blown ADC (F5,A10,FortiADC) with this feature, the following might be interesting for you.

 

Features

  • Supported Protocols: https, generic ssl, http, tcp, udp and generic ip
  • https offloading with optional crypto tuning
  • http redirect to https
  • HSTS and HPKP
  • secure cookies
  • simple http header manipulation (via web-proxy profile)
  • usable health checks
  • Automation through FGs standard REST API

Limitations

  • SNAT is limited to FGs interface IP 
  • Event logging can't show VIP or real server. Works with FAZ though
  • LB Monitor Dashboard shows only (static) configured state and not the health status
  • max 16 real server on 1HU devices
  • health checks might be redundant if real servers are reused in multiple VIPs

Missing

Advanced ADC features like

  • Content rewriting
  • Scripting (irules/aflex)
  • Caching
  • SNI

 

I like this feature because we didn't need a different dedicated box with individual handling, training, contracts and all. My hope: more admins use it and someone at FTN finds time to improve at least the dashboard limitation. Why did they make a dashboard that is static???

 

Regards,

Dirk

17 REPLIES 17
Anonymous
Not applicable

 
Thank you for using the Community Forum. We appreciate the information you have shared in the forum, although we think it is better suited to be an article instead so that everyone can make use of this useful information. We will work on this to create an article. We thank you for this great information.
 
Thanks,
DirkDuesentrieb
New Contributor

Hello @Anonymous ,

 

yes I'll need help - I don't know where/how to create an article.

 

Regards,

Dirk

DirkDuesentrieb
New Contributor

Hello all,

please note that at time of writing this, http-multiplex must be unset! Otherwise some clients will have connectivity issues in case of a realserver going down, because rebalancing of sessions with existing cookies will not work.

 

Regards,

Dirk

Debbie_FTNT

Hey Dirk,

at the moment, (KB) articles can only be created by Staff, not other community members.

I'm not sure if this will change, but I will reach out to the dedicated community team regarding your thread to see what can be done :).

Again, thanks for compiling the information in such an easily accessible format!

+++ Divide by Cucumber Error. Please Reinstall Universe and Reboot +++
jintrah_FTNT
Staff
Staff

Hi Dirk,

 

The SNAT is not limited to interface IP, we can have IP-Pools for SNAT.

 

jintrah_FTNT_0-1652861648710.png

 

best regards,

Jin

jintrah_FTNT

The realtime health monitor is available in the dashboard with healthcheck status. A sample below,

 

jintrah_FTNT_1-1652862126927.png

 

best regards,

Jin

 

jintrah_FTNT

Dear Dirk,

 

You mentioned "Event logging can't show VIP or real server. Works with FAZ though"

 

But I think whatever generated on FortiGate is only viewable in FAZ. Is there any sample log you can provide which you didnt see on FortiGate but on FAZ(RAW log please and no csv, please).

 

Best regards,

Jin

DirkDuesentrieb

Hello @jintrah_FTNT ,

ok, to put it more clearly: there is no column for VIP, so you can not filter on it.
columns.png

 

It is possible to check every log lines details to find the VIP.

log details.png

 

But ist is not the same as with FAZ, where you can see the VIP as a column and filter on it.

faz.png

 

Regards,

Dirk

jintrah_FTNT

Hi Dirk,

 

Thanks to make it clear about the search fields/column options in FAZ, rather misunderstanding for logs being unavailable on FortiGate.

 

Best regards,

Jin

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors