Hot!Firewall HA with two ISP

Author
baris
New Member
  • Total Posts : 2
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/06/05 00:53:51
  • Status: offline
2018/06/05 01:25:32 (permalink) 6.0
0

Firewall HA with two ISP

Hi guys, 
How can I apply this HA mode on for this topology ? 
I have two isp and two different wan ip network. How can I archive this ? 
I tried active-passive ha but due to nat interface rule it didn't work. 
 
Regards, 
Baris.
 
 

Attached Image(s)

#1

5 Replies Related Threads

    ahmedsf
    Bronze Member
    • Total Posts : 24
    • Scores: 4
    • Reward points: 0
    • Joined: 2017/12/24 03:00:02
    • Status: offline
    Re: Firewall HA with two ISP 2018/06/05 05:32:04 (permalink)
    0
    Hi,
    Do you have the router before FW or ISP link is directly connecting into WAN ports?
     
    In any case, suggestion is to keep the device priority 200 and heartbeat interface priority 50, 50 on both ports
    #2
    ahmedsf
    Bronze Member
    • Total Posts : 24
    • Scores: 4
    • Reward points: 0
    • Joined: 2017/12/24 03:00:02
    • Status: offline
    Re: Firewall HA with two ISP 2018/06/05 05:33:54 (permalink)
    0
    on which ports you have connected both FW's to each other to create HA? Let me know.
    #3
    baris
    New Member
    • Total Posts : 2
    • Scores: 0
    • Reward points: 0
    • Joined: 2018/06/05 00:53:51
    • Status: offline
    Re: Firewall HA with two ISP 2018/06/05 11:13:07 (permalink)
    0
    Hi Ahmed, 
    I think I solve the topology in right manner. 
    Since the buildings are seperated for each fw my topology going to like that. 

     
    Although I didn't apply for today. At the moment Side A fw connected Wan interface is WAN1
    Side B Wan interface WAN2 port connected to the ISP. 
    Monitor interface both Wan1 and Wan2 selected. 
    If ports down switching is so slow. Takes serious time. 5-6 min sometimes.
    I think it will be corrected after fixing the topology like above. 
    What do you think ? 
     
    Regards, 
    Baris. 
     
     

    Attached Image(s)

    #4
    ericli_FTNT
    Gold Member
    • Total Posts : 127
    • Scores: 4
    • Reward points: 0
    • Joined: 2018/02/08 11:12:27
    • Status: offline
    Re: Firewall HA with two ISP 2018/06/05 14:10:43 (permalink)
    0
    In an HA cluster, all members share the same configuration for fail-over purpose. For your requirements, I would suggest you take a look at SD-WAN.
    #5
    dotco
    New Member
    • Total Posts : 1
    • Scores: 0
    • Reward points: 0
    • Joined: 2019/10/04 10:10:42
    • Status: offline
    Re: Firewall HA with two ISP 2019/10/04 10:42:24 (permalink)
    0
    Hi Boris,
    I have same topology with you, i use SD wan for ISP fail over.
    and cisco swtich above the Fortigate,
    can you help me with the cisco switch configuration for isp link and interface to the Fortigate Wan port ?
    it will very helpful for me.
     
    many thanks,
    .co
    #6
    Jump to:
    © 2019 APG vNext Commercial Version 5.5