Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ascendmax
New Contributor

HA/Distributed Clustering Across Two Buildings

I am trying to design an HA setup with two firewalls running active/passive in two different buildings. I have fiber and switches between the two so layer 2 connectivity for the HA traffic is not a problem. But I have two ISP links at each location with different public IPs. Can I create failover between the two in the scenario? From what I can tell from the documentation, the active/passive clustering will create an identical config on the passive firewall.

 

Thanks,

-mike

7 REPLIES 7
aagrafi
Contributor II

That is correct. Both FGs will have identical configuration. If you want to have clustering in this scenario, you must have dual WAN links at both FGs and pass one WAN link of each FG to the remote side. In other words, between the FGs and the SPs there should be a switch.

 

I hope you understand the topology as I explained it ;)

ascendmax

aagrafi - Thanks for your reply. So it looks like what I'm trying to do is not possible. I do have dual WAN links are both locations but they have different public IP addresses. We are set up like this for example:

 

FG Site A

WAN1 - 10.10.10.1 (Comcast)

WAN2 - 10.10.20.1 (Verizon FIOS)

 

FG Site B

WAN1 - 172.28.1.1 (Level 3)

WAN2 - 172.30.1.1 (Cogent)

 

aagrafi

Hmmm. So, it seems you have 4 different SPs... It is still possible, but you'll need more cables. Check the attached.

Andreas

ascendmax

Andreas,

Would each FG have all four WAN IPs?

Thanks,

-mike

aagrafi

Yes, but there won't be any conflict, because one of the FGs will be in stand-by. In fact, both FGs will have exactly the same config.

Andreas

ascendmax

Andreas,

Would I need an FG with four physical WAN ports?

Thanks,

-mike

aagrafi

Not necessarily. You can do VLANs in the FG, but you'll definitely need two switches with sufficient physical ports.

Don't forget that you'll need additionally at least one physical port for the heartbit.

Cheers

Andreas

Labels
Top Kudoed Authors