92
01-28006-0068-20041105
Fortinet Inc.
Configuring an HA cluster
System config
13
If you are configuring a NAT/Route mode cluster, power off the FortiGate unit and
then repeat this procedure for all the FortiGate units in the cluster. Once all of the units
are configured, continue with
“To connect a FortiGate HA cluster” on page 92
.
14
If you are configuring a Transparent mode cluster, reconnect to the web-based
manager.
You may have to wait a few minutes before you can reconnect.
15
Go to
System > Status
.
16
Select Change to Transparent Mode and select OK to switch the FortiGate unit to
Transparent mode.
17
Power off the FortiGate unit.
18
Repeat this procedure for all of the FortiGate units in the cluster then continue with
“To
connect a FortiGate HA cluster” on page 92
.
To connect a FortiGate HA cluster
Use the following procedure to connect a cluster operating in NAT/Route mode or
Transparent mode. Connect the FortiGate units in the cluster to each other and to
your network. You must connect all matching interfaces in the cluster to the same hub
or switch. Then you must connect these interfaces to their networks using the same
hub or switch.
Fortinet recommends using switches for all cluster connections for the best
performance.
The FortiGate units in the cluster use cluster ethernet interfaces to communicate
cluster session information, synchronize the cluster configuration, and report
individual cluster member status. The units in the cluster are constantly
communicating HA status information to make sure that the cluster is operating
properly. This cluster communication is also called the cluster heartbeat.
Inserting an HA cluster into your network temporarily interrupts communications on
the network because new physical connections are being made to route traffic through
the cluster. Also, starting the cluster interrupts network traffic until the individual
FortiGate units in the cluster are functioning and the cluster completes negotiation.
Cluster negotiation normally takes just a few seconds. During system startup and
negotiation all network traffic is dropped.
1
Connect the cluster units.
• Connect the internal interfaces of each FortiGate unit to a switch or hub connected
to your internal network.
• Connect the WAN1 interfaces of each FortiGate unit to a switch or hub connected
to your external network.
• Connect the DMZ2 interfaces of the FortiGate units to the same switch or hub. By
default the DMZ2 interfaces are used for HA heartbeat communication. These
interfaces should be connected together for the HA cluster to function.
• Optionally connect the WAN2 interfaces of each FortiGate unit to a switch or hub
connected a second external network.
• Optionally Connect the DMZ1 interfaces of the FortiGate units to another switch or
hub.
Содержание FortiGate FortiGate-100A
Страница 24: ...24 01 28006 0068 20041105 Fortinet Inc FortiLog documentation Introduction...
Страница 46: ...46 01 28006 0068 20041105 Fortinet Inc Installing and using a backup firmware image System status...
Страница 72: ...72 01 28006 0068 20041105 Fortinet Inc Transparent mode VLAN settings System network...
Страница 80: ...80 01 28006 0068 20041105 Fortinet Inc DHCP IP MAC binding settings System DHCP...
Страница 114: ...114 01 28006 0068 20041105 Fortinet Inc Access profile options System administration...
Страница 232: ...232 01 28006 0068 20041105 Fortinet Inc CLI configuration Firewall...
Страница 244: ...244 01 28006 0068 20041105 Fortinet Inc peergrp Users and authentication...
Страница 320: ...320 01 28006 0068 20041105 Fortinet Inc service smtp Antivirus...
Страница 366: ...366 01 28006 0068 20041105 Fortinet Inc syslogd setting Log Report...
Страница 380: ...380 01 28006 0068 20041105 Fortinet Inc Glossary...
Страница 388: ...388 01 28006 0068 20041105 Fortinet Inc Index...