We are running 3x FGT100E&F - 2x FGT400D - 2x FGT500E 1x FGT600D 4x FGT1000C 1xFGT1200D Clusters in a-a mode.
Starting with the first a-a on FGT1000A (V3.0) in 2007 I can only report it is working great.
The best measure I can provide is the enduser experience: We always start with a single FGT and introduce the second FGT after a few weeks, when configuration is "solid". The feedback we get from the (End-) users is always "what have you done, Network is much more responsive I'm happy" ... after introducing a-a.
We implement mostly in environments where all/each Network-Segments (up to 100 VLAN) needs to be heavyly protected by AntiVirus, WebFilter, AppControl(!) and IPS. Especially AppControl can slow down the overall performance dramatically if applied on every VLAN; a-a is then, at least to our experience, best choice to balance the load.
With the introduction of the FGT100, a-a was pushed by FortiGate in a good way, but, that is at least my feeling, since many Forum's "do not like" a-a ... FortiGate over the years kept the functionality but does not realy push it forward; A shame.
Regarding TroubleShooting / Diagnostics:
In very rare cases we turned of the second device, made diagnostics and brought the a-a back in Service after TroubleShooting was finished.
We had never to TroubleShoot an a-a problem OR related to a-a !
So, what are the week points:
- In case the Master goes down: SSL VPN user will loose their connections and have to re-connect.
- We suggest FortiAnalyzer (!)
(We are not using vdom ... NO experience here)
These are the settings we have the best experience with:
config system ha
set group-id XX
set group-name "Name"
set mode a-a
set route-ttl 30
set session-pickup enable
set override disable
set priority 250 -> on Master
set priority 150 -> on secondary device
set load-balance-all enable
Design: Make sure you connect the FortiGate(s) to a Core Switch, we preferred always 2x Switches with VLT and created mLAG's (LACP) with by far better performance than connecting to Stack or single Switch(!)
I realy hope a-a gets more attraction which then may force FortiNet to invest more in this great functionallity!!!
Give it a try, get more for your money, it is easy to go back, IF at all, to a-p ...
post edited by SEI - 2021/04/21 02:24:07