Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Wenel
New Contributor

Problems setting load balancer, Firewall limitation or bad architecture?

Hi all,

 

I am having problems following this configuration scheme

https://help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-load-balancing-52/ldb_examples.htm

 

The architecture of my services is a bit different, in my case the nodes (real servers) that I want to balance have redundancy in different ports and I don't know what is the correct way to configure this. For example: 10.31.101.41:443 10.31.101.41:8443 10.31.101.42:443 10.31.101.42:8443...

When I try to configure a real server over TCP and port X it does not allow me create another real server with the same IP but another different port, how can I solve this? 

Thanks in advance

3 REPLIES 3
Wenel
New Contributor

Can someone help me please?

Dave_Hall
Honored Contributor

The examples from that link appears to be setting up a VIP to point or rather listen in for a "virtual IP", the real server IPs are mapped accordingly - there is no port assignment used on the real servers IPs.  The VIPs itself specific the port(s) used.

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C

NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
poundy

can you describe what your IP/port combinations above are representing?  Are they all equivalent end-points (all offer the same capability) or are they in some way special/different?  Remember that load balancing is intending to spread load across real servers, and you show that you only have 2x servers but each with 2x endpoints, I can understand why a second endpoint with different port may not be catered for. 

 

But if you really wanted to do this it's likely you'd need a TAC engineer to guide you here. Personally I'd try looking at the configuration in CLI and see if there's different validations going on in than in the GUI that might get you through?

 

 

Labels
Top Kudoed Authors