Hi community, I am going to implement many FortiSwitches as access
switches. I have read that FortiSwitches supports MCLAG but not stack.
Then, my first question is: 1. I am thinking of configuring them as
independent switches, not MCLAG, because whe...
Hi team, I have some doubts about integrating remote FortiSwitches to
FortiGate. I have read this document, but I still have
doubts:https://docs.fortinet.com/document/fortiswitch/7.6.3/fortilink-guide/801182/fortilink-mode-over-a-layer-3-network
This...
Hi community, Looking at the following post, it seems FGT-1 sends the
SYN to FGT-2 through the LAN switch.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGate-HA-A-A-cluster-3-way-TCP-handshake/ta-p/197467
In the following situation, ...
Hi community, I have a doubt regarding FortiGate HA active-active mode.
There are some articles explaining this mode operation, I have taken
this
one:https://www.fortinetguru.com/2016/10/natroute-mode-active-active-cluster-packet-flow/
Briefly and wi...
Hi community, I have upgraded an active/standby cluster of two
FortiGates, but the process is the opposite that what I thought. The
cluster HA override setting is disabled, so the uptime takes precedence
over the firewall priority. This is my initial...
Hi AEK, Yes, I understand. But in case we monitor link 1 and primary
fails over, there will not be load balance because primary will not be
able to forward packets to secondary through switch, is that right?
Regards,Julián
Hi AEK, If link 1 goes down even syn from client will not reach the
primary FW, the default gateway of the client will simply not be
reachable anymore. In that case the active-active HA still works but is
useless, since your client network is just is...
Hi Yuri, Very well explained. I thought DNS filtering needs to use
FortiGuard DNS servers because it must use FortiGuard DNS service for
DNS lookups, but I understand the FortiGate redirect DNS queries to
FortiGuard DNS servers.On the other hand, doe...
Hi everyone, Old post but I am wondering the same. If I understand well,
Web filter gives you more control over the things you can allow or
block, in addition you don't need to use the FortiGuard DNS servers, so
you don't have this limitation. Then, ...