Fortinet white logo
Fortinet white logo

Administration Guide

Management access

Management access

Effective management of an HA cluster requires establishing reliable administrative access to both the primary and secondary units. Depending on your network topology and security requirements, you can configure management access using shared data interfaces or dedicated administrative ports.

This section covers the following methods for configuring and optimizing cluster management:

Topic

Summary

Out-of-band management with reserved management interfaces

This method involves reserving a dedicated physical interface exclusively for management traffic. This allows for direct access to individual cluster units (including the secondary unit) and segregates administrative traffic, such as SNMP, logging, and remote authentication, from production data traffic.

In-band management

This method utilizes existing network interfaces for administrative access. It does not require a dedicated physical port, allowing management traffic to flow through the same subnets as user traffic. This section details how to configure management IPs on cluster interfaces.

Routing NetFlow data over the HA management interface

This advanced configuration utilizes the reserved management interface to offload bandwidth-intensive telemetry data. This ensures that NetFlow traffic does not consume bandwidth on production data ports.

Management access

Management access

Effective management of an HA cluster requires establishing reliable administrative access to both the primary and secondary units. Depending on your network topology and security requirements, you can configure management access using shared data interfaces or dedicated administrative ports.

This section covers the following methods for configuring and optimizing cluster management:

Topic

Summary

Out-of-band management with reserved management interfaces

This method involves reserving a dedicated physical interface exclusively for management traffic. This allows for direct access to individual cluster units (including the secondary unit) and segregates administrative traffic, such as SNMP, logging, and remote authentication, from production data traffic.

In-band management

This method utilizes existing network interfaces for administrative access. It does not require a dedicated physical port, allowing management traffic to flow through the same subnets as user traffic. This section details how to configure management IPs on cluster interfaces.

Routing NetFlow data over the HA management interface

This advanced configuration utilizes the reserved management interface to offload bandwidth-intensive telemetry data. This ensures that NetFlow traffic does not consume bandwidth on production data ports.