94
01-28007-0144-20041217
Fortinet Inc.
HA
System config
To connect a FortiGate HA cluster
Use the following procedure to connect a cluster operating in NAT/Route mode or
Transparent mode. Connect the FortiGate units in the cluster to each other and to
your network. You must connect all matching interfaces in the cluster to the same hub
or switch. Then you must connect these interfaces to their networks using the same
hub or switch.
Fortinet recommends using switches for all cluster connections for the best
performance.
The FortiGate units in the cluster use cluster ethernet interfaces to communicate
cluster session information, synchronize the cluster configuration, and report
individual cluster member status. The units in the cluster are constantly
communicating HA status information to make sure that the cluster is operating
properly. This cluster communication is also called the cluster heartbeat.
Inserting an HA cluster into your network temporarily interrupts communications on
the network because new physical connections are being made to route traffic through
the cluster. Also, starting the cluster interrupts network traffic until the individual
FortiGate units in the cluster are functioning and the cluster completes negotiation.
Cluster negotiation normally takes just a few seconds. During system startup and
negotiation all network traffic is dropped.
1
Connect the cluster units.
• Connect the internal interfaces of each FortiGate unit to a switch or hub connected
to your internal network.
• Connect the WAN1 interfaces of each FortiGate unit to a switch or hub connected
to your external network.
• Connect the DMZ interfaces of the FortiGate units to another switch or hub.
• Optionally connect the WAN2 interface of each FortiGate unit to a switch or hub
connected a second external network.
Содержание FortiGate FortiGate-60M
Страница 12: ...Contents 12 01 28007 0144 20041217 Fortinet Inc Index 369 ...
Страница 43: ...System status Changing the FortiGate firmware FortiGate 60M Administration Guide 01 28007 0144 20041217 43 ...
Страница 44: ...44 01 28007 0144 20041217 Fortinet Inc Changing the FortiGate firmware System status ...
Страница 74: ...74 01 28007 0144 20041217 Fortinet Inc FortiGate IPv6 support System network ...
Страница 82: ...82 01 28007 0144 20041217 Fortinet Inc Dynamic IP System DHCP ...
Страница 116: ...116 01 28007 0144 20041217 Fortinet Inc Access profiles System administration ...
Страница 234: ...234 01 28007 0144 20041217 Fortinet Inc Protection profile Firewall ...
Страница 246: ...246 01 28007 0144 20041217 Fortinet Inc CLI configuration Users and authentication ...
Страница 278: ...278 01 28007 0144 20041217 Fortinet Inc CLI configuration VPN ...
Страница 340: ...340 01 28007 0144 20041217 Fortinet Inc Using Perl regular expressions Spam filter ...
Страница 358: ...358 01 28007 0144 20041217 Fortinet Inc CLI configuration Log Report ...
Страница 376: ...376 01 28007 0144 20041217 Fortinet Inc Index ...