FortiGate 60F HA Cluster Build

  Рет қаралды 49,712

Fortinet Guru

Fortinet Guru

Күн бұрын

Let's try this again. This is a video about how to build an HA Cluster out of two FortiGate 60F's and 2 FortiSwitch 124F's.
Buy Hardware: bit.ly/2QZVeqh
Get Consulting: bit.ly/36FinSU
My Other Projects:
Office Of The CISO: bit.ly/3HGMH1o
Packet Llama: bit.ly/3SEX3H4
###### SOCIAL LINKS ######
Twitter: bit.ly/2WXiRAv
Facebook: bit.ly/3eigz4D
Instagram: bit.ly/3cZneAz
######################

Пікірлер: 95
@darkhsu
@darkhsu 2 жыл бұрын
Sounds like you have just been through a rough day. Cheer up Mike, we do like your videos. 😉
@RaviChinasamy
@RaviChinasamy 2 жыл бұрын
Great to see that you are back at last. 😊
@clevtrev96
@clevtrev96 Жыл бұрын
The GOAT of FortiGate tutorials
@JoeyGarcia
@JoeyGarcia 2 жыл бұрын
I have a pair of 500D and 300D FortiGate firewalls. Each pair are in HA. Definitely nice to have in the enterprise! I'm planning on introducing a pair of 1024D's and hopefully utilize MC-LAG
@drostoker
@drostoker 2 жыл бұрын
Missed your videos. Looking forward to more in the near future.
@Stingray7423
@Stingray7423 2 жыл бұрын
Great as always!
@thewaterboy2013
@thewaterboy2013 2 жыл бұрын
Thanks for this, Mike! Been very curious about the process for this for some time, but haven't had two forti's to do this with or had anyone to watch do this.
@MBNhub
@MBNhub 2 жыл бұрын
you can do it forite vm
@thewaterboy2013
@thewaterboy2013 2 жыл бұрын
@@MBNhub I hadn't looked into the vms for Forti, can you do them for free/evaluation for a lab setup?
@JasonsLabVideos
@JasonsLabVideos 2 жыл бұрын
Wicked Video Mike, I did a HA setup too with my 61e's & pair of Cisco 24 port Switches :) Keep these videos coming !
@Darkk6969
@Darkk6969 2 жыл бұрын
I have a pair of 601E at data center and corporate office. Both using HA setup. Although I am not using two Fortinet switches as HA. They're configured with a group of 4 ports VLANs to handle the WAN, LAN, VOIP and DMZ. It's not ideal but it makes moving the physical cables from one switch to another easy if one should die. I also have a third switch as a cold spare in the rack. I did the same thing with the WatchGuards before we moved to Fortinet products. Some ISP providers will give you two WAN drops for your HA setup. I agree on using active and passive in the HA cluster so you don't get into a pinch about performance if you need to do maintenance or one should die. There is one thing I did like about the WatchGuard's license policy for active / passive setup is that you only need live security on both devices. IPS and other licensed services are only required on the active device.
@DeesoSaeed
@DeesoSaeed 2 жыл бұрын
Recently configured two Fortigates 200Fin HA and two Fortiswitch 524D as core with MCLAG ICL, then a buch of 148Fs hanging from the latter for edge switching
@ivarutne6228
@ivarutne6228 2 жыл бұрын
I love Fortigate because is extremely simple and extremely clear (best GUI) vs Palo Alto, SRX and so on. Team from Fortinet does good work.
@portalend
@portalend 2 жыл бұрын
Could you do a video on transitioning from static routing to dynamic routing like OSPF? I'm sure lots of people start out on entirely static routes then reach a scale where it becomes a pain to manage. I'm interested in the specifics on how the static routing will interact with the dynamic routes during the transition. Asking for a friend. 😉
@PabloMartinez-ds3og
@PabloMartinez-ds3og 7 ай бұрын
Excellent tank you :)................
@dgilvani
@dgilvani 2 жыл бұрын
Tight! Tight!! TY
@quikmcw
@quikmcw 2 жыл бұрын
Would like to make a request: Can you do a video setting up two AP's as a bridge, connecting two FSW together with fortilink and multiple vlan operation? This configuration is stumping the fortinet engineers!
@gastonsalazar5052
@gastonsalazar5052 2 жыл бұрын
gracias Genio!!!
@terrykilpatrick5799
@terrykilpatrick5799 2 жыл бұрын
I find your content very helpful, the only thing that would help is if you could speak a bit more loudly or add a bit more volume to the audio for sometimes it's difficult to understand clearly what you are saying. Thanks and keep them coming.👍
@DhammikaNirodha
@DhammikaNirodha Жыл бұрын
Great
@balla2172
@balla2172 2 жыл бұрын
Gave you credit with corporate armor for the whole new network I just bought. I'd love to get another 601 so I could do ha but the budget just isn't there unfortunately
@ottawa29m
@ottawa29m 2 жыл бұрын
1 - What options should we enable on the CLI to have a smooth failover? 2 - Can you do a video on using a firewall as layer 2, and maybe touch on how this works in a cluster?
@databeestje
@databeestje Жыл бұрын
You can reset the HA timer, that will make it do a seamless failover.
@mohamedabdullahi3665
@mohamedabdullahi3665 Жыл бұрын
thanks well legend
@dergarmark7189
@dergarmark7189 2 жыл бұрын
Good video! Could you please make a video of a deep dive into the HA options such as monitoring ports and manual failover and failback? Maybe you could show HA status in the cli too. You could show how an firmware update works with HA.
@mrStarcKbe
@mrStarcKbe 2 жыл бұрын
Sometimes is happens that your cluster isn’t in sync through the gui. The following command through cli can help you with that check “diag sys ha checksum cluster”. This way you are certain that the cluster is ok. You can setup more HB interfaces and perhapse a dedicated one for the tcp sessions to failover. Then you have that group id which I highly recommend to change if the customer has multiple Fortigate clusters. At last the command “set override enable” and “set override-wait-time 300” so the cluster will automatically fallback to the primary device after a failover. Not going into details like changing the ether packets. 👍
@adipapaianus5723
@adipapaianus5723 Жыл бұрын
@@mrStarcKbe You are 110% right! Every HA cluster should have "set group-id XY" configured. I had a situation in the past where WAN1 was constantly flapping due to another Fortigate HA cluster on the WAN subnet! It was like crazy! Once I have configured group-id pain went away and HA is running rock solid for the past 3 years on 6.2.x release.
@ashrafhelal9354
@ashrafhelal9354 2 жыл бұрын
Thanks for doing those Videos, they are very good. i have a question about "port channel" can we create port channel two cables between the FortiGate1 going one cable to the Fortiswitch1 and the other fortiSwitch2: doing the same with FortiGate2?
@gobofraggel7383
@gobofraggel7383 2 жыл бұрын
The only firewall I know is Sophos XG and now XGS. I configured HA for a client that is a 24/7 company with 7 warehouses and it was easy and it worked as expected. I have always been intrigued by FortiGate. Which is better?
@lazzybug007
@lazzybug007 4 ай бұрын
Well it all look easy for you... I never did a irl setup so far ..hope I will be successful 🤞.. being a fresher in this field without any support..it feels so difficult 😭
@jamesmyers777
@jamesmyers777 Жыл бұрын
Would have been good to discuss session pickup more, what types of sessions can and can't be failed over and other ideas like that. I would also like to know more about active active, any chance of ajother HA video mate?
@serlegar
@serlegar 2 жыл бұрын
That mac address story remind me of that day when I installed Fortigate cluster in a data center where another client had already another Fortigate cluster. We were both connected to the same datacenter internet provider switch and obviously spoofing the same mac address...
@FortinetGuru
@FortinetGuru 2 жыл бұрын
Yeah. The key around that is to change the HA group ID to a different number.
@mrStarcKbe
@mrStarcKbe 2 жыл бұрын
@@FortinetGuru true
@adipapaianus5723
@adipapaianus5723 Жыл бұрын
same story here ... always set group-id for a HA cluster.
@oralmolden1158
@oralmolden1158 2 жыл бұрын
A while back I added MCLAG and you mentioned it, any plans to make a video on that. Also have a NAC deployment and was wondering if you had plans to make a video for pointers, maybe I missed something, maybe I missed a lot.
@ian230187
@ian230187 Жыл бұрын
Hey...have a doubt here.... Did you get a chance to check the CAM LAN switch where the secondary ports sre connected? They do not populate physical mac address of the Fortigate nic.... wanted to understand the concept
@zSnowFlakesTV
@zSnowFlakesTV 2 жыл бұрын
Guru, I'm having a really hard time finding a way to build a whitelist in fortiOS 7.0.2, could you make a video talking about white and blacklist rules? how to build it properly? I've been researching reddit and forti cookbock but I just can't figure out what I'm doing wrong. love your videos I learned a lot from you keep it up !!
@dirkmare6445
@dirkmare6445 2 жыл бұрын
Hi Mike, new to fortigate fw I recently watched your video about firmware upgrades and your three rules.. I Would really like to use video content filtering but its only included in V7 and not V6.4.6 So I guess my question is for new out of the box setup is it save/advisable to upgrade to newer firmware's and when do you bite the bullet to do upgrades in production? EXAMPLE: GA minus 2 versions Thanks
@ashrafhelal9354
@ashrafhelal9354 2 жыл бұрын
13:03 i was wondering, if there isn't a DHCP, how they are going to get a new management IP? and can we do it through cli?
@boyd8871
@boyd8871 3 ай бұрын
Hello, can you explain more why the frotigate is degraded when primary/slave failed in active-active setup?
@RichardDePas
@RichardDePas 2 жыл бұрын
Set this up about 6 months ago with 101F Frotigates and 124F FortiSwitches. Opted for the FortiLink Split interfaces. Probably more of a pain than I needed to go through. Had one switch drop offline and needed a hard reboot to get it going again. Never did find the root cause.
@FortinetGuru
@FortinetGuru 2 жыл бұрын
Yeah, I've had that happen as well.
@RichardDePas
@RichardDePas 2 жыл бұрын
@@FortinetGuru Any clue why it happened? Or is that a bug in 7.0 code?
@pavelbrusnicky2723
@pavelbrusnicky2723 2 жыл бұрын
How about fortigate vs multiple switches session? Thanks.
@salvadorseekatzrisquez2947
@salvadorseekatzrisquez2947 2 жыл бұрын
My experience, is that HA makes the maintenance window longer because the delay after one reboots we need to wait for them to Sync again. Depending on the customer some connections to the Internet will break during HA so for some customer its more outages than less, I am not advocating against redundancy, it's def. nice to have. But a single reboot for upgrade. Maybe Fortinet could improve the way they upgrade. Also I noticed that this on Active/Passive. Active/Active is not really a fact, I have tried to work with Fortinet Support and they have said that it doesn't really work to avoid outages.
@mrStarcKbe
@mrStarcKbe 2 жыл бұрын
True on the A-A part, but not completely true the HA part. You can set it to override disable so it won’t switch back to the primary unit. This way you can initiate it your self. The first failover will always be faster then a single unit. 👍
@MladenMarinov
@MladenMarinov 2 жыл бұрын
Hi, I like you lectures. Unfortunately I have problem you did not review - passing the multicast traffic from the provider to STB. Can I contact you to guide me about this?
@dmitriykott769
@dmitriykott769 2 жыл бұрын
Hellow, please make review about new version fortios 7.2!
@allferryrocha2698
@allferryrocha2698 2 жыл бұрын
Hey Mike, good time for you to make a video on how to block Log4J on Fortigate FW.
@mrStarcKbe
@mrStarcKbe 2 жыл бұрын
Use IPS signatures and use them as they should be used on “severity” level. So use the IPS filter to block medium,high and critical severity levels. Put them on ALL policy’s! Also on internal once so a breached client can’t use that a signature (medium,high or cricital). For traffic coming from internet use that same IPS filter. And for servers where you can use SSL Server protection put that on too so you can inspect https traffic too.
@headdstrong983
@headdstrong983 2 жыл бұрын
Hello from Russia. btw recently i configured Fortigate 200 mode with HA mode in prodaction.
@askmethod
@askmethod 10 күн бұрын
13:03 from where did u bring floating IP
@knithiyanandhan
@knithiyanandhan Жыл бұрын
Need a Help: I need to allow port 3306 from outside company one particular IP address?
@cankitchourasia
@cankitchourasia 2 жыл бұрын
I see you did not select the "Monitor Interface" option under HA. Curious to know how will FWs detect failover scenario.
@FortinetGuru
@FortinetGuru 2 жыл бұрын
Once this foetigate cluster is installed on location I will pick the monitored interfaces based on need. 99% chance I will use the fortilink aggregate and the wan1 port.
@frankperera3885
@frankperera3885 Жыл бұрын
can someone explain how to do the process mentioned in 12:40 ?
@billwoodall562
@billwoodall562 2 жыл бұрын
Good video, I do have a question. Can you HA an existing firewall? I have a 201F and bought a backup unit.
@FortinetGuru
@FortinetGuru 2 жыл бұрын
Sure can
@billwoodall562
@billwoodall562 2 жыл бұрын
@@FortinetGuru I am assuming the same process just make the primary firewall the master first?
@renhe108
@renhe108 2 жыл бұрын
Do you consider to set monitor port in HA settings? if the port down, the failover will happen right away.
@FortinetGuru
@FortinetGuru 2 жыл бұрын
That is correct. You would configure monitoring of the port for physical outages. Link monitors will assist if the upstream link is "green" but not passing traffic.
@shanegreentree7851
@shanegreentree7851 8 ай бұрын
hi. I am looking at buying two 60f, can I use unifi switch to set up ha
@FortinetGuru
@FortinetGuru 8 ай бұрын
You can.
@abdomordy6935
@abdomordy6935 Жыл бұрын
how can i deploy Fortigate FW HA active-active on AWS in muli AZ environment with autoscalling?
@FortinetGuru
@FortinetGuru Жыл бұрын
Hmmm, good question.
@IxTapewormxI
@IxTapewormxI 2 жыл бұрын
Hope your doing alright Chuck its been a few months. Can you show us how to configure a FortiSwitch 224E in Stand alone mode? I've been having issues getting mine to work correctly with the management vlan.
@FortinetGuru
@FortinetGuru 2 жыл бұрын
I am alive, but in the famous words of Big Hero 6....I am not fast.... haha
@salvadorseekatzrisquez2947
@salvadorseekatzrisquez2947 2 жыл бұрын
I like the sound of your keyboard and mouse, what do you use?
@salvadorseekatzrisquez2947
@salvadorseekatzrisquez2947 2 жыл бұрын
8:30
@rodneyaltamera4057
@rodneyaltamera4057 2 жыл бұрын
HI Fortinet Guru I have a question. I have a setup that is in HA Cluster (Active-Active). The problem when I update the firmware both Firewalls will loose connection and restart. I was expecting that the Primary will be updated first, then the backup will be next. Can you give me any advise what I am doing wrong. Thanks
@mrStarcKbe
@mrStarcKbe 2 жыл бұрын
Normally you login on the primary device so the upgrade command is send to the primary device. Then it checks the checksum and if it’s good it will send the update to the secondary device. It them will start updating. In an active/active the load balancing is turned of so all traffic will be route towards primary device.
@Firecross666
@Firecross666 2 жыл бұрын
Do you have any interest or experience in configuring FortiWeb?
@MuhammadWaqas-fq3yg
@MuhammadWaqas-fq3yg 2 жыл бұрын
Can we test the HA Cluster on EVE-NG ? Did any one try it ?
@hennessy6996
@hennessy6996 2 жыл бұрын
Hi, do you usually do Central NAT? Is your preference Flow-based inspection?
@FortinetGuru
@FortinetGuru 2 жыл бұрын
Majority of my firewalls are done with UTM Profile mode and standard NAT. I have started doing more and more with NGFW Policy mode and Central NAT (especially conversions from PAN devices)
@rosatechnocrat2206
@rosatechnocrat2206 2 жыл бұрын
From a working mode or faster traffic Flow mode is better , But in flow mode some the features are not allowed as the in flow mode connection is not terminated on Fortigate. But If you want deep inspection then Proxy mode is better.
@uneeds2122
@uneeds2122 2 жыл бұрын
Hello Fortinet Guru just one question please I have fortigate which i made web filter on it but some user uses VPN to passthrow web filter how I can fix this, what the method to solve this thank you
@FortinetGuru
@FortinetGuru 2 жыл бұрын
Block vpn access at the application level.
@amro_hadi
@amro_hadi 2 жыл бұрын
hey, fortinet Guru, do you have any videos for VDOMs?
@rosatechnocrat2206
@rosatechnocrat2206 2 жыл бұрын
What kind of videos you need For Vdoms ..
@amro_hadi
@amro_hadi Жыл бұрын
@@rosatechnocrat2206 What are Vdoms for start, what are the use cases when Vdoms can be useful and how the traffic flows in Vdoms.
@rikerud
@rikerud 2 жыл бұрын
What equipment are you running your self this days?
@FortinetGuru
@FortinetGuru 2 жыл бұрын
Still cruising on an 80e-poe at the house
@rikerud
@rikerud 2 жыл бұрын
@@FortinetGuru using Forti AP's with it as well?
@thebocop
@thebocop Жыл бұрын
Confused on how you have this hooked up to the switches...
@FortinetGuru
@FortinetGuru Жыл бұрын
In what way? A of each FortiGate goes to each Switch and B of each FortiGate does the same. Split link on the Fortilink makes it full mesh. Other options are A of each FortiGate to switch 1 and B of each FortiGate to switch 2 with split-fortilink off.
@thebocop
@thebocop Жыл бұрын
@@FortinetGuru I found out I had to delete a few interfaces to make them available for the HA ports on the 60F.... (4 and 5)
@raphaelfigueredo5524
@raphaelfigueredo5524 10 ай бұрын
deus do fortinet
@xephael3485
@xephael3485 2 жыл бұрын
1:35 Fortigates use HSRP? Don't use Cisco trash... VRRP, etc.
@IsmailNuzaifKokky
@IsmailNuzaifKokky 2 жыл бұрын
.
@ITS-yk5ky
@ITS-yk5ky Ай бұрын
The part about the device priority is wrong. The lower the number, the higher the priority.
@FortinetGuru
@FortinetGuru Ай бұрын
No. In HA higher priority wins. In routing, lower priority wins.
@khalil4826
@khalil4826 Жыл бұрын
bla bla bla ...
@waqaskhan-cx5dx
@waqaskhan-cx5dx 2 жыл бұрын
I have to two fortigate firwall 201 f and want to configure cluster HA. And Also have to Wan connection. I need a little help with that. Can you please share your email address so we can discuss it sir.
Full Fortinet Stack Environment
27:39
Fortinet Guru
Рет қаралды 66 М.
The child was abused by the clown#Short #Officer Rabbit #angel
00:55
兔子警官
Рет қаралды 24 МЛН
Osman Kalyoncu Sonu Üzücü Saddest Videos Dream Engine 170 #shorts
00:27
ОДИН ДЕНЬ ИЗ ДЕТСТВА❤️ #shorts
00:59
BATEK_OFFICIAL
Рет қаралды 8 МЛН
A Computer Cluster Made With BROKEN PCs
24:34
Hardware Haven
Рет қаралды 204 М.
Fortinet: Configuring HA on FortiGate firewalls
10:47
ToThePoint Fortinet
Рет қаралды 28 М.
VLANs SAVED my home network
17:23
SpaceRex
Рет қаралды 64 М.
DO NOT design your network like this!! // FREE CCNA // EP 6
19:36
NetworkChuck
Рет қаралды 3,1 МЛН
Fortigate HA configuration
57:48
TAN Kirivann
Рет қаралды 24 М.
Common FortiSwitch Topologies: Ring and MCLAG
20:55
ToThePoint Fortinet
Рет қаралды 9 М.
The child was abused by the clown#Short #Officer Rabbit #angel
00:55
兔子警官
Рет қаралды 24 МЛН