Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
avilt
New Contributor

Fortigate HA Setup Guide

I am looking for a detailed guide on HA setup, all I see on the Internet are basic setup steps.

I have a few queries with regards to HA on fortigate

1. Do I need to assign IP addresses on HA interfaces?

2. Do I need to setup the IP addresses on both firewalls for other (non-HA) interfaces? Is it going to get the IP from master during the fail-over?

3.  How about MGMT interface in HA pair, do I need to assign IP on both firewalls?

4 REPLIES 4
Toshi_Esumi
SuperUser
SuperUser

They used to have a separate handbook only for HA but I can't find it any more. So check HA section of the handbook.

https://fortinetweb.s3.amazonaws.com/docs.fortinet.com/v2/attachments/c6546940-7683-11e9-81a4-005056...

 

All answers should be in there but,

1. No, HB interface needs no IP

2. Regularly backup/slave unit don't need to configure anything else other than HA config and a few part, like MGMT interfaces, that wouldn't be copied over. During the sync up process after becoming a backup/slave, all the other config including interfaces will be copied over from master. Just make sure it would become the backup/slave by reading the primary selection flowchart.

3. You don't have to have an IP on MGMT interface if you don't plan to use outband managment. I use it when when the config becomes un-syncable from the master and needs a hand-modification and upload.

avilt

Thank you.

Is the MGMT interface out of band management?

Toshi_Esumi

If you configured it to be in HA config.

gpinero
New Contributor II

About this topic, I have a doubt. In HA setup the VRRP ip address is unique for the cluster but each Fortigate has an ip address. 

When VRRP is working only the VIP is accesible and you can manage one Fortigate or other with: execute ha manage

This is right?

Well, imagine that:

FGT1 10.10.10.10

FGT2 10.10.10.11

VRRP 10.10.10.12

If one equipment overlap the ip address of (for example) FGT1. 

There would be a problem?

What are the ips of each Fortigate used once the cluster is formed?

 

I hope to have explained.

 

Thanks

 

 

 

Labels
Top Kudoed Authors