Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
minion
New Contributor

Implementation Design

Be fair warned, I am new to FortiGate, so I may be asking some trivial question. I have been tasked with implementation of new FortiGate equipment in a remote office that will VPN back to corporate. Due to the VIP status of the location we purchase two each – ISP Circuit, FortiGate 201E and FortiSwitch 248B. For the HQ location we purchased two FortiGate 301E. I contacted support and I have read about 195 pages of the Cookbook, but am getting a little short on time and still without a solid feeling about the implementation. So I thought I would try out the Forum for support.

Remote office Design 1. Stack the switches using redundant logical interface with standby enabled (Primary link to sw1 standby link to last switch sw2) shown in FortiNet Support ("HA-mode FortiGate units managing a stack of several FortiSwitch units") ? 2. Setup FortiGates in HA Active-Passive or Active-Active? Most all documentation prefers Active-Passive.

ISP Redundancy 3. Can the two ISP WAN links be brought into the FortiSwitch stack and then split to each FortiGate? How would the switch ports and FortiGate ports configured for the these connections? Seems most people are recommending to cheapo dumb switches between ISP and FortiGates, but that seems counter productive when I have foriswitches.

 

I have more questions but don’t want to overload with my first post.  Bottom line is that I am looking for best practice from an installers perspective that will be stable and reliable.

Thanks!

0 REPLIES 0
Labels
Top Kudoed Authors