Re: fortigate Failover query
Your physical design is flawed...the firewalls are not meshed. You need to connect FG-INT1 to FG-DC2 and FG-INT2 to FG-DC1 so that you have true redundancy. This can most easily be done physically if you can put a switch between the FG-INT and FG-DC FortiGates, but you could also achieve this logically with additional routed links. Then it wouldn't matter that FG-INT1 was still operational when FG-DC2 took over.
Another thought is that you potentially don't even need 4 firewalls... Assuming there's enough capacity, you can put the DC and perimeter all on one HA pair using different VDOMs if necessary. We're a small shop, so we just run everything on one set of boxes that I manage (single VDOM).
- Daniel Hamilton