Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jimmyd4ng3r
New Contributor

VRRP - how to track another interface? and how to use vrdst ?

Hi, I have a 2 fortigates protecting two subnets. The primary fortigate has a higher priority for both interfaces than the secondary firewall. How to I setup the VRRP so that if one of the interfaces on the primary fortigates drops, the secondary takes over the primary role for BOTH subnets? At the moment, the way I see it, if only one interface drops on the primary, it shall still be the master for the other network and thus create asymmetric routing. In the cisco world, you would track the other interface as well but there doesn' t seem to be a solution in the fortigate world that I can see. Also, can someone update me more for the vrdst option ?
4 REPLIES 4
nyx01xnyx
New Contributor

I'm facing the same issue

 

jimmyd4ng3r wrote:
Hi, I have a 2 fortigates protecting two subnets. The primary fortigate has a higher priority for both interfaces than the secondary firewall. How to I setup the VRRP so that if one of the interfaces on the primary fortigates drops, the secondary takes over the primary role for BOTH subnets? At the moment, the way I see it, if only one interface drops on the primary, it shall still be the master for the other network and thus create asymmetric routing. In the cisco world, you would track the other interface as well but there doesn' t seem to be a solution in the fortigate world that I can see. Also, can someone update me more for the vrdst option ?

berimbau
New Contributor

Hi,

 

Depending on which version is your Fortigate.

But on 5.2 there is a new parameter "vrgrp" , with this you can put all your vrrp interface on the same group, this way the state is tracked and all the vrrp interface on the same group will fail back.

 

Regards

emnoc
Esteemed Contributor III

FWIW: The cisco like track is not available in a FortiOS, so you have no means to do this.

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
dpsguard
New Contributor

Sorry for posting in the old thread.

 

1. Is there a way to force master unit to become backup if attached ISP circuit on master goes down (interface monitoring or virtual wan link, health check)? In my case, I will be using two ISPs on each FGT, so SD-WAN interface and thus looking for failure of both ISPs at the same time. These two ISPs will be two circuits from same ISP, just one high speed and another low speed. The second unit will have cellular Internet (to start with, later on, I will connect high speed circuit to both firewalls).

2. Is vrdst IP of something on the internet (like Google DNS) be used to track absence of route thru the ISP to trigger making master as backup? The CLI guide is confusing as it states vrdst IP to be next hop address.

3. Does a master unit losing the VRRP advertisement response, remain master or it decreases its priority to become slave? Else both units can become master at the same time?

4. Hopefully SD-WAN and VRRP can be used simultaneously.

 

 Thanks

Labels
Top Kudoed Authors