
FortiGate-400 Installation and Configuration Guide Version 2.50 MR2
FortiGate-400 Installation and Configuration Guide
75
High availability
Fortinet achieves high availability (HA) using redundant hardware and the FortiGate
Clustering Protocol (FGCP). The FortiGate units in the HA cluster enforce the same
overall security policy and share the same configuration settings. You can add up to
32 FortiGate units to an HA cluster. Each FortiGate unit in an HA cluster must be the
same model and be running the same FortiOS firmware image.
FortiGate HA is device redundant. If one of the FortiGate units in an HA cluster fails,
all functions, all established firewall connections, and all IPSec VPN sessions
1
are
maintained by the other FortiGate units in the HA cluster.
The FortiGate units in the cluster use dedicated HA ethernet interfaces to
communicate cluster session information and report individual system status. The
units in the cluster are constantly communicating HA status information to make sure
the cluster is functioning properly. For this reason, the connection between the HA
ports of all of the FortiGate units in the cluster must be well maintained. An interruption
of this communication can cause unpredictable results.
You can manage the cluster by connecting to any cluster interface configured for
management access.
FortiGate units can be configured to operate in active-passive (A-P) or active-active
(A-A) HA mode. Active-active and active-passive HA are supported in both NAT/Route
and Transparent modes.
This chapter provides an overview of HA functionality and describes how to configure
and manage HA clusters in NAT/Route mode and in Transparent mode.
•
Active-passive HA
•
Active-active HA
•
HA in NAT/Route mode
•
HA in Transparent mode
•
Managing the HA cluster
•
Advanced HA options
Active-passive HA
An Active-passive (A-P) HA cluster, also referred to as hot standby HA, consists of a
primary FortiGate unit that is processing traffic and one or more subordinate FortiGate
units connected to the network and to the primary FortiGate unit but not processing
traffic.
1.HA does not provide session failover for PPPoE, DHCP, PPTP, and L2TP services.
Summary of Contents for FortiGate 400
Page 13: ...Contents FortiGate 400 Installation and Configuration Guide 13 Glossary 295 Index 299 ...
Page 14: ...Contents 14 Fortinet Inc ...
Page 44: ...44 Fortinet Inc Next steps Getting started ...
Page 74: ...74 Fortinet Inc Transparent mode configuration examples Transparent mode installation ...
Page 148: ...148 Fortinet Inc Providing DHCP services to your internal network Network configuration ...
Page 168: ...168 Fortinet Inc Customizing replacement messages System configuration ...
Page 200: ...200 Fortinet Inc Content profiles Firewall configuration ...
Page 258: ...258 Fortinet Inc Logging attacks Network Intrusion Detection System NIDS ...
Page 294: ...294 Fortinet Inc Configuring alert email Logging and reporting ...
Page 298: ...298 Fortinet Inc Glossary ...
Page 308: ...308 Fortinet Inc Index ...