Hot!Fortigate HA Setup Guide

Author
avilt
Bronze Member
  • Total Posts : 35
  • Scores: 0
  • Reward points: 0
  • Joined: 2014/02/11 03:16:33
  • Status: offline
2019/05/31 13:08:30 (permalink)
0

Fortigate HA Setup Guide

I am looking for a detailed guide on HA setup, all I see on the Internet are basic setup steps.
I have a few queries with regards to HA on fortigate
1. Do I need to assign IP addresses on HA interfaces?
2. Do I need to setup the IP addresses on both firewalls for other (non-HA) interfaces? Is it going to get the IP from master during the fail-over?
3.  How about MGMT interface in HA pair, do I need to assign IP on both firewalls?
#1

4 Replies Related Threads

    Toshi Esumi
    Expert Member
    • Total Posts : 1566
    • Scores: 132
    • Reward points: 0
    • Joined: 2014/11/06 09:56:42
    • Status: offline
    Re: Fortigate HA Setup Guide 2019/05/31 14:07:45 (permalink)
    0
    They used to have a separate handbook only for HA but I can't find it any more. So check HA section of the handbook.
    https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/c6546940-7683-11e9-81a4-00505692583a/fortios-handbook-60.pdf
     
    All answers should be in there but,
    1. No, HB interface needs no IP
    2. Regularly backup/slave unit don't need to configure anything else other than HA config and a few part, like MGMT interfaces, that wouldn't be copied over. During the sync up process after becoming a backup/slave, all the other config including interfaces will be copied over from master. Just make sure it would become the backup/slave by reading the primary selection flowchart.
    3. You don't have to have an IP on MGMT interface if you don't plan to use outband managment. I use it when when the config becomes un-syncable from the master and needs a hand-modification and upload.
    #2
    avilt
    Bronze Member
    • Total Posts : 35
    • Scores: 0
    • Reward points: 0
    • Joined: 2014/02/11 03:16:33
    • Status: offline
    Re: Fortigate HA Setup Guide 2019/05/31 14:26:48 (permalink)
    0
    Thank you.
    Is the MGMT interface out of band management?
    #3
    Toshi Esumi
    Expert Member
    • Total Posts : 1566
    • Scores: 132
    • Reward points: 0
    • Joined: 2014/11/06 09:56:42
    • Status: offline
    Re: Fortigate HA Setup Guide 2019/05/31 14:30:15 (permalink)
    0
    If you configured it to be in HA config.
    #4
    gpinero
    New Member
    • Total Posts : 2
    • Scores: 0
    • Reward points: 0
    • Joined: 2017/03/16 06:58:04
    • Location: Spain
    • Status: offline
    Re: Fortigate HA Setup Guide 2019/06/14 21:51:20 (permalink)
    0
    About this topic, I have a doubt. In HA setup the VRRP ip address is unique for the cluster but each Fortigate has an ip address. 
    When VRRP is working only the VIP is accesible and you can manage one Fortigate or other with: execute ha manage
    This is right?
    Well, imagine that:
    FGT1 10.10.10.10
    FGT2 10.10.10.11
    VRRP 10.10.10.12
    If one equipment overlap the ip address of (for example) FGT1. 
    There would be a problem?
    What are the ips of each Fortigate used once the cluster is formed?
     
    I hope to have explained.
     
    Thanks
     
     
     
    #5
    Jump to:
    © 2019 APG vNext Commercial Version 5.5