Fortinet FortiController-5913C System Manual Download Page 9

FortiController-5913C system 

FortiController-5913C session-aware load balancing (SALB)

FortiController-5913C Session-Aware Load Balancing Cluster (SLBC) System Guide
10-500-259409-20160210

9

http://docs.fortinet.com/

As a session-aware load balancer, the FortiController-5913C maintains the state for each 
session and is capable of directing any session to any worker installed in the same 
chassis. This session-awareness means that all traffic being processed by a specific 
worker continues to be processed by the same worker. Session-awareness also means 
that more complex networking features such as network address translation (NAT), 
fragmented packets, complex UDP protocols, and complex protocols such as SIP that 
use pinholes, can be load balanced by the cluster.

In a FortiController-5913C load balanced cluster, when a worker that is processing SIP 
traffic creates a pinhole, this information is communicated to the FortiController-5913C. 
The FortiController-5913C then knows to distribute the voice and media sessions to this 
worker. 

The FortiController-5913C supports adding and removing workers from the cluster. So 
you can start with a small number of workers and add more as your requirements grow. 
When a new worker is added to a chassis slot and switched to forticontroller mode the 
cluster automatically detects it, synchronizes its configuration and begins sending new 
sessions to it, maintaining existing sessions on the workers that were already in the 
cluster. If a worker fails or is removed from the cluster, the FortiController-5913C detects 
its absence and re-balances and redistributes sessions to the remaining workers. 

The FortiController-5913C supports the following single-chassis SALB configurations:

One FortiController-5913C and up to 12 workers. The FortiController-5913C receives 
all sessions and load balances them to the workers. If the FortiController-5913C fails 
the cluster fails.

Two FortiController-5913Cs in HA mode and up to 12 workers. The primary 
FortiController-5913C receives all sessions and load balances them to the workers. If 
the primary FortiController-5913C fails, the backup FortiController-5913C takes its 
place.

Two FortiController-5913Cs in dual mode and up to 12 workers. Both 
FortiController-5913Cs receive and load balance sessions to the workers. If a 
FortiController-5913C fails the other FortiController-5913C continues to operate. All 
sessions processed by the failed FortiController-5913C are lost.

Four FortiController-5913Cs and up to 10 workers in a chassis with dual dual star 
architecture (such as the FortiGate-5144C). The FortiController-5913Cs in slots 1 and 
2 receive and load balance sessions to the workers. The FortiController-5913Cs in 
slots 1 and 3 and the FortiController-5913Cs in slots 2 and 4 form redundant pairs. If 
the FortiController-5913C in slot 1 fails, the FortiController-5913C in slot 3 takes over. 
If the FortiController-5913C in slot 2 fails, the FortiController-5913C in slot 4 takes 
over.

The SIP protocol uses known SIP ports for control traffic but dynamically uses a wide 
range of ports for voice and other media traffic. To successfully pass SIP traffic through 
a firewall, the firewall must use a session helper or application gateway to look inside the 
SIP control traffic and determine the ports to open for voice and media. To allow the 
voice and media traffic, the firewall temporarily opens these ports, creating what’s 
known as a pinhole that temporarily allows traffic on a port as determined by the SIP 
control traffic. The pinhole is closed when the voice or media session ends. 

Session-aware load balancing does not support traffic shaping.

Summary of Contents for FortiController-5913C

Page 1: ...ortiGate 5000 series documents are available from the FortiGate 5000 page of the Fortinet Technical Documentation web site http docs fortinet com Access to Fortinet customer services such as firmware...

Page 2: ...t is grounded This includes supply connections e g power strips not only direct connections to the branch circuit Mise la terre Assurez vous que tout l quipement est mis la terre Ceci comprend les con...

Page 3: ...own and Removing a FortiController 5913C board 17 Resetting a FortiController 5913C board 19 Troubleshooting 20 FortiController 5913C does not startup 20 FortiController 5913C status LED is flashing d...

Page 4: ...n 28 Customer service and support 28 Fortinet products End User License Agreement 28 Regulatory Notices 30 Federal Communication Commission FCC USA 30 Industry Canada Equipment Standard for Digital Eq...

Page 5: ...FortiGate 5001D workers can handle up to 40 Gbps of traffic FortiGate 5001B and FortiGate 5101C workers can handle up to 10 Gbps The FortiController 5913C can also provide 40 gigabit fabric and 1 gig...

Page 6: ...istribute sessions to workers installed in chassis slots 3 to 14 The speed of these interfaces cannot be changed You may need to use attenuators on these single or split interfaces if their optical po...

Page 7: ...shing Amber Network activity Off No link is established B1 and B2 Green The correct cable is connected to the interface and the connected equipment has power Flashing Green Network activity at the int...

Page 8: ...he same chassis can be added for redundancy or to increase the number of network interfaces You can also add a second chassis for chassis redundancy Table 2 FortiController 5913C connectors Connector...

Page 9: ...ons One FortiController 5913C and up to 12 workers The FortiController 5913C receives all sessions and load balances them to the workers If the FortiController 5913C fails the cluster fails Two FortiC...

Page 10: ...ler 5913C and up to 12 workers in each chassis The FortiController 5913C in one chassis receives all sessions and load balances them to the workers in that chassis If that FortiController 5913C fails...

Page 11: ...m a two chassis SLBC where each chassis would include a FortiController 5913C in slot 1 and optionally a second FortiController 5913C in slot 2 You then install the workers in slots 3 and up in each c...

Page 12: ...Controller 5913C session aware load balancing SALB FortiController 5913C system FortiController 5913C Session Aware Load Balancing Cluster SLBC System Guide 12 10 500 259409 20160210 http docs fortine...

Page 13: ...nstall SR SFP transceivers for normal operation of FortiController 5913C B1 and B2 front panel interfaces The FortiController 5913C ships with two SR SFP transceivers You can also configure the B1 and...

Page 14: ...right bottom of the FortiController 5913C front panel The mounting components on the left top of the front panel are the same but reversed The FortiController 5913C mounting components align the boar...

Page 15: ...ard power on and start up correctly FortiController 5913C boards are hot swappable The procedure for inserting a FortiController 5913C board into a chassis slot is the same whether or not the chassis...

Page 16: ...sides of the chassis slot Closing the handles draws the FortiController 5913C board into place in the chassis slot and into full contact with the chassis backplane The FortiController 5913C front pane...

Page 17: ...ontroller 5913C mounting components described in FortiController 5913C mounting components on page 14 to remove a FortiController 5913C board from an ATCA chassis slot FortiController 5913C boards are...

Page 18: ...s flashing and becomes solid blue 7 Open the handles to their fully open positions Opening the handles turns off the microswitch turns off all LEDs and ejects the board from the chassis slot You need...

Page 19: ...the FortiController 5913C board to use this procedure To complete this procedure you need An ATCA chassis with a FortiController 5913C board installed An electrostatic discharge ESD preventive wrist...

Page 20: ...ortiController 5913C board is receiving power and the handles are fully closed and you have restarted the chassis and the FortiController 5913C still does not start up the problem could be with FortiO...

Page 21: ...hould indicate that the boards are functioning normally This chapter includes the following topics SLBC licensing Connecting to the FortiController 5913C GUI Connecting to the FortiController 5913C CL...

Page 22: ...alancing settings By default you can connect to the FortiController 5913C GUI by browsing to https 192 168 1 99 Connecting to the FortiController 5913C CLI You can connect to the FortiController 5913C...

Page 23: ...ler 5913C board in chassis slot 1 3 Install the workers in chassis slots 3 4 and 5 4 Power on the chassis 5 Check the chassis and board LEDs to verify that all components are operating normally 6 Chec...

Page 24: ...as the FortiController 5913C management IP address 12 Connect FortiController 5913C front panel interface F1 to the Internet and front panel interface F2 to the internal network The workers see these...

Page 25: ...nto the FortiController 5913C GUI going to Load Balance Status and selecting the Config Master icon beside the primary worker which is always the top entry in the Worker Blade list Using the external...

Page 26: ...e workers in the cluster in a single operation from the worker web based manager The firmware running on all of the workers in the cluster is updated simultaneously 1 Log into the worker web based man...

Page 27: ...ssage Running Slot 6 Status Working Function Active Link Base Up Fabric Up Heartbeat Managment Good Data Good Status Message Running Slot 8 Status Working Function Active Link Base Up Fabric Up Heartb...

Page 28: ...ubleshooting how to articles examples FAQs technical notes and more Visit the Fortinet Knowledge Base at http kb fortinet com Comments on Fortinet technical documentation Send information about any er...

Page 29: ...press or implied except to the extent Fortinet enters a binding written contract signed by Fortinet s General Counsel with a purchaser that expressly warrants that the identified product will perform...

Page 30: ...this equipment in a residential area is likely to cause harmful interference in which case the user will be required to correct the interference at his own expense WARNING Any changes or modifications...

Reviews: