
Configuring the FortiGate for the Network
FortiGate-5000 series Installation Guide
01-28011-0259-20060210
13
Once the FortiGate-5000 modules are added to the HA cluster, the cluster functions
on your network as a single module with
n
interfaces where
n
is the number of
FortiGate-5000 modules multiplied by the available interfaces on the module. The
cluster manages communication and load balancing between the modules.
You can operate an HA cluster in NAT/Route or Transparent mode. For more
information on HA, see
“High availability installation” on page 32
.
Figure 3: HA network configuration in NAT/Route mode
Figure 4: HA network configuration in Transparent mode
Link
redundancy
If one of the links to a FortiGate unit in an HA cluster fails, all functions, all
established firewall connections, and all IPSec VPN sessions
a
are maintained
by the other FortiGate units in the HA cluster.
a.HA does not provide session failover for PPPoE, DHCP, PPTP, and L2TP services.
Device
redundancy
If one of the FortiGate units in an HA cluster fails, all functions, all established
firewall connections, and all IPSec VPN sessions are maintained by the other
FortiGate units in the HA cluster.
FortiGate-5001SX HA cluster in in NAT/Route
mode in a FortiGate-5020 chassis
Route mode policies
controlling traffic between
internal networks.
Internal network
DMZ network
Port1
192.168.1.99
Port 3
10.10.10.1
192.168.1.3
10.10.10.2
Port2
204.23.1.5
NAT mode policies controlling
traffic between internal and
external networks.
Internet
PSU A
PSU B
PWR ACC
STA IPM
CONSOLE
USB
1
2
3
4
5
6
7
8
PWR ACC
STA IPM
CONSOLE
USB
1
2
3
4
5
6
7
8
FortiGate-5001SX HA Cluster in Transparent
mode in a FortiGate-5020 chassis
192.168.1.2
Management IP
Port1
Internal network
192.168.1.3
Port2
192.168.1.1
Transparent mode policies
controlling traffic between
internal and external networks
204.23.1.5
(firewall, router)
Gateway to
public network
Internet
PSU A
PSU B
PWR ACC
STA IPM
CONSOLE
USB
1
2
3
4
5
6
7
8
PWR ACC
STA IPM
CONSOLE
USB
1
2
3
4
5
6
7
8