![Fortinet FortiWAN Handbook Download Page 129](http://html1.mh-extra.com/html/fortinet/fortiwan/fortiwan_handbook_2322088129.webp)
Inbound Load Balancing and Failover (Multihoming)
Load Balancing & Fault Tolerance
Signing
:
States for the key, Active or Standby for options. Keys in the active state are those
that are in use. Keys in standby state are not introduced into the zone.
Algorithm
:
Only RSASHA512 is supported. This field is visible only for Administrator permission.
Key Size
:
Only 2048 bits is supported. This field is visible only for Administrator permission.
Key Tag
:
Key ID.
Hash
:
Hash of the public key. Send the hash value to parent zone to generate a DS record.
Modulus
:
Public modulus for the keypair. This field is visible only for Administrator permission.
PublicExponent
:
Exponent for the public key. This field is visible for only Administrator permission.
PrivateExponent
:
Exponent for the private key. This field is visible for only Administrator permission.
Prime1
:
Prime number 1 for the keypair. This field is visible for only Administrator permission.
Prime2
:
Prime number 2 for the keypair. This field is visible for only Administrator permission.
Notice:
1. You can generate multiple key pairs in batches from the configuration panel. Generally one key pair is in Active
state for using while the other key pairs are in Standby state for manually key rollover at the appropriate time as
determined by your key management policy.
2. In case of replacement keys, it is strongly suggested to keep both new and old keys in Active state for at least one
TTL value. When the caching of records using the old keys in external name servers has expired, the old keys can
be deleted.
3. Before deleting DNSSEC keys from your domain, you have to delete the corresponded DS record from the parent
zone. Be careful that any mistake in the process of key replacement or delete might cause DNS queries to your
domain failure.
NS Record
Name Server
:
Enter server name's prefix . For example: if a server’s FQDN is "ns1.abc.com", enter
“ns1”.
IPv4 Address
:
Enter the IPv4 address corresponding to the name server.
IPv6 Address
:
Enter the IPv6 address corresponding to the name server.
A Record
Host Name
:
Enter the prefix name of the primary workstation. For example: if the name is "www.-
abc.com", enter “www”.
When
:
Options: All-Time/Busy/Idle
Source
:
Enter the IPv6/IPv4 address that the DNS query comes from.
FortiWAN Handbook
Fortinet Technologies Inc.
129