Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
FXE_FTNT
New Contributor II

HA of FortiManager

Hi guys,

Just have some questions about FortiManager HA, basically my environment is I have 2x DC where I want to put my FortiManager. I will be placing 1x FortiManager in each of my DC in my management segment/block and these have different subnet (e.g., DC1 = MgmtSubnetA and DC2 = MgmtSubnetB). 

 

1. Is it feasible to form FortiManager in HA if my primary and slave will have different subnet?

2. If question 1 is feasible, how will the FortiGate communicates to the FortiManager?

3. If question 1 is feasible, how will the FortiGate communicate to the Slave FortiManager in the event of Primary FortiManager goes down?

 

Thank you

6 REPLIES 6
DPadula
Staff
Staff

Hi FXE_FTNT

On FMG HA solution we don't call them master and slave, we called them primary and secondary. 

 

Here are the answers:

1. Yes, then can be on different subnets. The primary unit and the secondary units can be in the same location or different locations. FortiManager HA supports geographic redundancy so the primary unit and secondary units can be in different locations attached to different networks as long as communication is possible between them (for example, on the Internet, on a WAN, or in a private network (link 1)

2. FGT will talk the primary FMG using the FMG IP address configured on FGT.

3. On my understanding based on Fortinet documentation, because there are in different DC (so assuming different subnets) they cannot be setup as VRRP, so it will be a manual failover mode. 

 

More details can be found on the following links: 

link1 - https://docs.fortinet.com/document/fortimanager/7.4.2/administration-guide/568591/high-availability

link2 - https://docs.fortinet.com/document/fortimanager/7.4.2/administration-guide/800686/configuring-ha-opt...

 

FXE_FTNT
New Contributor II

Hi @DPadula , if you say manual failover, do you mean manual promotion of the secondary FMG?

vraev
Staff
Staff
FXE_FTNT
New Contributor II

Hi @vraev , is my understanding correct, the VRRP failover mechanism of FMG can be done even if they have different subnet?

vraev

Hi @FXE_FTNT ,

 

Sorry for the delay but I had a chance to test the following standard HA cluster configuration recently.

 

So after the test I could tell that it is possible when is used standard HA setup. Both FMG had a route to each other setup in their configuration. FW policy that is allowing the traffic between them in both direction and no nat.

 

Hope this will help you.

Best,

 
 

 

V.R.
vraev
Labels
Top Kudoed Authors