System Config
HA
FortiGate-5000 series Administration Guide
01-28008-0013-20050204
99
1
Power on the FortiGate unit to be configured.
2
Connect to the web-based manager.
3
Give the FortiGate unit a unique host name.
See
“To change FortiGate host name” on page 37
. Use host names to identify
individual cluster units.
4
Go to
System > Config > HA
.
5
Select HA.
6
Select the HA mode.
7
Select a Group ID for the cluster.
The Group ID must be the same for all FortiGate units in the HA cluster.
8
Optionally change the Unit Priority.
See
“Unit Priority” on page 94
.
9
If required, select Override master.
See
“Override Master” on page 95
.
10
Enter and confirm a password for the HA cluster.
11
If you are configuring Active-Active HA, select a schedule.
See
“Schedule” on page 95
.
12
Select Apply.
The FortiGate unit negotiates to establish an HA cluster. When you select apply you
may temporarily lose connectivity with the FortiGate unit as the HA cluster negotiates
and because the FGCP changes the MAC address of the FortiGate unit interfaces
(see
“Group ID” on page 94
). To be able to reconnect sooner, you can update the ARP
table of your management PC by deleting the ARP table entry for the FortiGate unit.
13
If you are configuring a NAT/Route mode cluster, power off the FortiGate unit and
then repeat this procedure for all the FortiGate units in the cluster. Once all of the units
are configured, continue with
“To connect a FortiGate HA cluster” on page 100
.
14
If you are configuring a Transparent mode cluster, reconnect to the web-based
manager.
You may have to wait a few minutes before you can reconnect.
15
Go to
System > Status
.
16
Select Change to Transparent Mode and select OK to switch the FortiGate unit to
Transparent mode.
17
Power off the FortiGate unit.
Note:
The following procedure does not include steps for configuring heartbeat devices and
interface monitoring. Both of these HA settings should be configured after the cluster is up and
running.
Note:
By default, port 9 and port 10 are configured as heartbeat devices. These interfaces are
only used for HA cluster communication and are not physically accessible. These interfaces are
not visible on the web-based manager, but they are visible on the CLI.
Содержание FortiGate FortiGate-5020
Страница 86: ...86 01 28008 0013 20050204 Fortinet Inc Dynamic IP System DHCP ...
Страница 118: ...118 01 28008 0013 20050204 Fortinet Inc FortiManager System Config ...
Страница 254: ...254 01 28008 0013 20050204 Fortinet Inc CLI configuration User ...
Страница 318: ...318 01 28008 0013 20050204 Fortinet Inc CLI configuration Antivirus ...
Страница 350: ...350 01 28008 0013 20050204 Fortinet Inc Using Perl regular expressions Spam filter ...
Страница 370: ...370 01 28008 0013 20050204 Fortinet Inc CLI configuration Log Report ...
Страница 382: ...382 01 28008 0013 20050204 Fortinet Inc Glossary ...
Страница 402: ...402 01 28008 0013 20050204 Fortinet Inc Index ...