Fortinet white logo
Fortinet white logo

Administration Guide

Advanced operations

Advanced operations

This section details complex deployment scenarios and specialized configurations for HA clusters. These advanced operations extend beyond standard setups, allowing for geographically distributed redundancy, customized synchronization behaviors, and integration with specific network infrastructures.

This section covers the following advanced topics and configurations:

Topic

Summary

Distributed HA clusters

Deploying cluster units across different physical locations to achieve geo-redundancy.

HA between remote sites over managed FortiSwitches

Utilizing the switch layer (MCLAG) to carry heartbeat signals between sites instead of dedicated fiber connections.

Cluster virtual MAC addresses

Managing how virtual MAC addresses are assigned to prevent conflicts and ensure reliable failover.

Disabling stateful SCTP inspection

Preventing packet drops in asymmetric routing scenarios within multi-homing topologies.

Manual failover of FortiGates deployed in an A-P architecture with VWP and using wildcard VLAN

Ensuring that non-native VLANs correctly update their paths during a failover in Virtual Wire Pair setups.

HA using a hardware switch to replace a physical switch

Deploying clusters without external switches by utilizing internal hardware switch configurations.

Override FortiAnalyzer and syslog server settings

Configuring secondary units to send logs to different destinations or use different source IPs than the primary unit.

FGCP HA between FortiGates of the same model with different AC and DC PSUs

Establishing redundancy across different power grids by clustering units with mixed power supply types.

Querying autoscale clusters for FortiGate VM

Verifying the status and synchronization of autoscale environments from secondary VM members.

Abbreviated TLS handshake after HA failover

Enabling faster session resumption for TLS traffic after a failover event.

HA with 802.3ad aggregate interfaces

Combine multiple physical links into a single logical interface.

HA with redundant interfaces

Combining two or more physical interfaces into a single redundant interface.

DHCP and PPPoE behavior in FortiGate HA clusters

How FortiGate HA clusters handle scenarios where units obtain their own IP addresses using DHCP or PPPoE, and how they operate when functioning as a DHCP server or DHCP relay.

Advanced operations

Advanced operations

This section details complex deployment scenarios and specialized configurations for HA clusters. These advanced operations extend beyond standard setups, allowing for geographically distributed redundancy, customized synchronization behaviors, and integration with specific network infrastructures.

This section covers the following advanced topics and configurations:

Topic

Summary

Distributed HA clusters

Deploying cluster units across different physical locations to achieve geo-redundancy.

HA between remote sites over managed FortiSwitches

Utilizing the switch layer (MCLAG) to carry heartbeat signals between sites instead of dedicated fiber connections.

Cluster virtual MAC addresses

Managing how virtual MAC addresses are assigned to prevent conflicts and ensure reliable failover.

Disabling stateful SCTP inspection

Preventing packet drops in asymmetric routing scenarios within multi-homing topologies.

Manual failover of FortiGates deployed in an A-P architecture with VWP and using wildcard VLAN

Ensuring that non-native VLANs correctly update their paths during a failover in Virtual Wire Pair setups.

HA using a hardware switch to replace a physical switch

Deploying clusters without external switches by utilizing internal hardware switch configurations.

Override FortiAnalyzer and syslog server settings

Configuring secondary units to send logs to different destinations or use different source IPs than the primary unit.

FGCP HA between FortiGates of the same model with different AC and DC PSUs

Establishing redundancy across different power grids by clustering units with mixed power supply types.

Querying autoscale clusters for FortiGate VM

Verifying the status and synchronization of autoscale environments from secondary VM members.

Abbreviated TLS handshake after HA failover

Enabling faster session resumption for TLS traffic after a failover event.

HA with 802.3ad aggregate interfaces

Combine multiple physical links into a single logical interface.

HA with redundant interfaces

Combining two or more physical interfaces into a single redundant interface.

DHCP and PPPoE behavior in FortiGate HA clusters

How FortiGate HA clusters handle scenarios where units obtain their own IP addresses using DHCP or PPPoE, and how they operate when functioning as a DHCP server or DHCP relay.