Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
CHAMPE
New Contributor

FORTIGATE HA - switching best practice

Hello everyone

I'd like some insight on the following

I have two fortigates in a cluster both in A-A. Sync is working fine, the links from the cluster are terminating on a switch. Ideally, what i would have done is configure a port channel and set a random vlan for it for the incoming interfaces from the cluster. I would then set the same vlan for the outgoing interface.

In a scenario where vlans have been defined at the switch level and the outgoing interface has a vlan already configured on it. What would be the best practice ?

1 REPLY 1
saneeshpv_FTNT

Hi @CHAMPE ,

 

I am not sure If I could completely understand your use case.

 

But here is a quick reference to Active-Active HA Setup.

 

https://docs.fortinet.com/document/fortigate/7.4.1/administration-guide/357558/ha-active-active-clus...

 

With respect to VLAN and Port channel, if you have limitation on the availability of separate ports for inside and outside, you can have port channel configured on Fortigate and Switch and use sub interface with different VLAN ID's for Inside and Outside.

 

Best Regards,

Labels
Top Kudoed Authors