92
01-28007-0068-20041203
Fortinet Inc.
Configuring an HA cluster
System config
To connect a FortiGate HA cluster
Use the following procedure to connect a cluster operating in NAT/Route mode or
Transparent mode. Connect the FortiGate units in the cluster to each other and to
your network. You must connect all matching interfaces in the cluster to the same hub
or switch. Then you must connect these interfaces to their networks using the same
hub or switch.
Fortinet recommends using switches for all cluster connections for the best
performance.
The FortiGate units in the cluster use cluster ethernet interfaces to communicate
cluster session information, synchronize the cluster configuration, and report
individual cluster member status. The units in the cluster are constantly
communicating HA status information to make sure that the cluster is operating
properly. This cluster communication is also called the cluster heartbeat.
Inserting an HA cluster into your network temporarily interrupts communications on
the network because new physical connections are being made to route traffic through
the cluster. Also, starting the cluster interrupts network traffic until the individual
FortiGate units in the cluster are functioning and the cluster completes negotiation.
Cluster negotiation normally takes just a few seconds. During system startup and
negotiation all network traffic is dropped.
1
Connect the cluster units.
• Connect the internal interfaces of each FortiGate unit to a switch or hub connected
to your internal network.
• Connect the WAN1 interfaces of each FortiGate unit to a switch or hub connected
to your external network.
• Connect the DMZ2 interfaces of the FortiGate units to the same switch or hub. By
default the DMZ2 interfaces are used for HA heartbeat communication. These
interfaces should be connected together for the HA cluster to function.
• Optionally connect the WAN2 interfaces of each FortiGate unit to a switch or hub
connected a second external network.
• Optionally Connect the DMZ1 interfaces of the FortiGate units to another switch or
hub.
Summary of Contents for FortiGate 100A
Page 12: ...Contents 12 01 28007 0068 20041203 Fortinet Inc ...
Page 24: ...24 01 28007 0068 20041203 Fortinet Inc FortiLog documentation Introduction ...
Page 72: ...72 01 28007 0068 20041203 Fortinet Inc Transparent mode VLAN settings System network ...
Page 80: ...80 01 28007 0068 20041203 Fortinet Inc DHCP IP MAC binding settings System DHCP ...
Page 114: ...114 01 28007 0068 20041203 Fortinet Inc Access profile options System administration ...
Page 232: ...232 01 28007 0068 20041203 Fortinet Inc Profile CLI configuration Firewall ...
Page 244: ...244 01 28007 0068 20041203 Fortinet Inc peergrp Users and authentication ...
Page 276: ...276 01 28007 0068 20041203 Fortinet Inc ipsec vip VPN ...
Page 338: ...338 01 28007 0068 20041203 Fortinet Inc Configuring the banned word list Spam filter ...
Page 356: ...356 01 28007 0068 20041203 Fortinet Inc syslogd setting Log Report ...
Page 374: ...374 01 28007 0068 20041203 Fortinet Inc Index ...