FortiGate 60F HA Cluster Build

  Рет қаралды 54,212

Fortinet Guru

Fortinet Guru

Күн бұрын

Пікірлер: 98
@clevtrev96
@clevtrev96 2 жыл бұрын
The GOAT of FortiGate tutorials
@darkhsu
@darkhsu 3 жыл бұрын
Sounds like you have just been through a rough day. Cheer up Mike, we do like your videos. 😉
@JC-dx3fy
@JC-dx3fy Ай бұрын
Thank you! You have been my main goto for Fortigate issues!
@RaviChinasamy
@RaviChinasamy 3 жыл бұрын
Great to see that you are back at last. 😊
@JoeyGarcia
@JoeyGarcia 3 жыл бұрын
I have a pair of 500D and 300D FortiGate firewalls. Each pair are in HA. Definitely nice to have in the enterprise! I'm planning on introducing a pair of 1024D's and hopefully utilize MC-LAG
@Darkk6969
@Darkk6969 2 жыл бұрын
I have a pair of 601E at data center and corporate office. Both using HA setup. Although I am not using two Fortinet switches as HA. They're configured with a group of 4 ports VLANs to handle the WAN, LAN, VOIP and DMZ. It's not ideal but it makes moving the physical cables from one switch to another easy if one should die. I also have a third switch as a cold spare in the rack. I did the same thing with the WatchGuards before we moved to Fortinet products. Some ISP providers will give you two WAN drops for your HA setup. I agree on using active and passive in the HA cluster so you don't get into a pinch about performance if you need to do maintenance or one should die. There is one thing I did like about the WatchGuard's license policy for active / passive setup is that you only need live security on both devices. IPS and other licensed services are only required on the active device.
@thewaterboy2013
@thewaterboy2013 3 жыл бұрын
Thanks for this, Mike! Been very curious about the process for this for some time, but haven't had two forti's to do this with or had anyone to watch do this.
@thewaterboy2013
@thewaterboy2013 2 жыл бұрын
@MBNHub I hadn't looked into the vms for Forti, can you do them for free/evaluation for a lab setup?
@JayZx777
@JayZx777 2 ай бұрын
I know I am late to the party, but I am doing the Fortigate implementation with the Cisco world (C9200 and C9300 L3). My Cisco's are set in HSRP and running inter vlan routing, hence the interfaces on the Fortis are setup as /30 and I run RIP on the Fortis, and EIGRP on rest of Cisco's environment then redistribute RIP to EIGRP LOL hahaha. Maybe it is time to ditch EIGRP and go with OSPF, but so far so good. I am not sure if I will ditch the C9200 and C9300s yet to Forti Switches, yet who knows. The future plan is to set the FortiNAC and test the integration with stuff like Meraki APs and Kanji for MAC auth. Anyhow, thanks for sharing the video, nice and simple!
@DeesoSaeed
@DeesoSaeed 2 жыл бұрын
Recently configured two Fortigates 200Fin HA and two Fortiswitch 524D as core with MCLAG ICL, then a buch of 148Fs hanging from the latter for edge switching
@ivarutne6228
@ivarutne6228 2 жыл бұрын
I love Fortigate because is extremely simple and extremely clear (best GUI) vs Palo Alto, SRX and so on. Team from Fortinet does good work.
@drostoker
@drostoker 3 жыл бұрын
Missed your videos. Looking forward to more in the near future.
@ottawa29m
@ottawa29m 2 жыл бұрын
1 - What options should we enable on the CLI to have a smooth failover? 2 - Can you do a video on using a firewall as layer 2, and maybe touch on how this works in a cluster?
@databeestje
@databeestje 2 жыл бұрын
You can reset the HA timer, that will make it do a seamless failover.
@balla2172
@balla2172 2 жыл бұрын
Gave you credit with corporate armor for the whole new network I just bought. I'd love to get another 601 so I could do ha but the budget just isn't there unfortunately
@portalend
@portalend 2 жыл бұрын
Could you do a video on transitioning from static routing to dynamic routing like OSPF? I'm sure lots of people start out on entirely static routes then reach a scale where it becomes a pain to manage. I'm interested in the specifics on how the static routing will interact with the dynamic routes during the transition. Asking for a friend. 😉
@vanmax8259
@vanmax8259 28 күн бұрын
I like your video. Thanks man
@JasonsLabVideos
@JasonsLabVideos 3 жыл бұрын
Wicked Video Mike, I did a HA setup too with my 61e's & pair of Cisco 24 port Switches :) Keep these videos coming !
@lazzybug007
@lazzybug007 9 ай бұрын
Well it all look easy for you... I never did a irl setup so far ..hope I will be successful 🤞.. being a fresher in this field without any support..it feels so difficult 😭
@dergarmark7189
@dergarmark7189 2 жыл бұрын
Good video! Could you please make a video of a deep dive into the HA options such as monitoring ports and manual failover and failback? Maybe you could show HA status in the cli too. You could show how an firmware update works with HA.
@mrStarcKbe
@mrStarcKbe 2 жыл бұрын
Sometimes is happens that your cluster isn’t in sync through the gui. The following command through cli can help you with that check “diag sys ha checksum cluster”. This way you are certain that the cluster is ok. You can setup more HB interfaces and perhapse a dedicated one for the tcp sessions to failover. Then you have that group id which I highly recommend to change if the customer has multiple Fortigate clusters. At last the command “set override enable” and “set override-wait-time 300” so the cluster will automatically fallback to the primary device after a failover. Not going into details like changing the ether packets. 👍
@adipapaianus5723
@adipapaianus5723 2 жыл бұрын
@@mrStarcKbe You are 110% right! Every HA cluster should have "set group-id XY" configured. I had a situation in the past where WAN1 was constantly flapping due to another Fortigate HA cluster on the WAN subnet! It was like crazy! Once I have configured group-id pain went away and HA is running rock solid for the past 3 years on 6.2.x release.
@quikmcw
@quikmcw 2 жыл бұрын
Would like to make a request: Can you do a video setting up two AP's as a bridge, connecting two FSW together with fortilink and multiple vlan operation? This configuration is stumping the fortinet engineers!
@Stingray7423
@Stingray7423 2 жыл бұрын
Great as always!
@ashrafhelal9354
@ashrafhelal9354 2 жыл бұрын
Thanks for doing those Videos, they are very good. i have a question about "port channel" can we create port channel two cables between the FortiGate1 going one cable to the Fortiswitch1 and the other fortiSwitch2: doing the same with FortiGate2?
@oralmolden1158
@oralmolden1158 2 жыл бұрын
A while back I added MCLAG and you mentioned it, any plans to make a video on that. Also have a NAC deployment and was wondering if you had plans to make a video for pointers, maybe I missed something, maybe I missed a lot.
@titangaming9649
@titangaming9649 2 ай бұрын
How do you wire the WAN ports on them? WAN1 and WAN 2 on both firewalls. If you only have one WAN drop from the ISP how does this work?
@jamesmyers777
@jamesmyers777 2 жыл бұрын
Would have been good to discuss session pickup more, what types of sessions can and can't be failed over and other ideas like that. I would also like to know more about active active, any chance of ajother HA video mate?
@boyd8871
@boyd8871 8 ай бұрын
Hello, can you explain more why the frotigate is degraded when primary/slave failed in active-active setup?
@PabloMartinez-ds3og
@PabloMartinez-ds3og Жыл бұрын
Excellent tank you :)................
@RichardDePas
@RichardDePas 3 жыл бұрын
Set this up about 6 months ago with 101F Frotigates and 124F FortiSwitches. Opted for the FortiLink Split interfaces. Probably more of a pain than I needed to go through. Had one switch drop offline and needed a hard reboot to get it going again. Never did find the root cause.
@FortinetGuru
@FortinetGuru 3 жыл бұрын
Yeah, I've had that happen as well.
@RichardDePas
@RichardDePas 3 жыл бұрын
@@FortinetGuru Any clue why it happened? Or is that a bug in 7.0 code?
@serlegar
@serlegar 3 жыл бұрын
That mac address story remind me of that day when I installed Fortigate cluster in a data center where another client had already another Fortigate cluster. We were both connected to the same datacenter internet provider switch and obviously spoofing the same mac address...
@FortinetGuru
@FortinetGuru 3 жыл бұрын
Yeah. The key around that is to change the HA group ID to a different number.
@mrStarcKbe
@mrStarcKbe 2 жыл бұрын
@@FortinetGuru true
@adipapaianus5723
@adipapaianus5723 2 жыл бұрын
same story here ... always set group-id for a HA cluster.
@terrykilpatrick5799
@terrykilpatrick5799 2 жыл бұрын
I find your content very helpful, the only thing that would help is if you could speak a bit more loudly or add a bit more volume to the audio for sometimes it's difficult to understand clearly what you are saying. Thanks and keep them coming.👍
@gobofraggel7383
@gobofraggel7383 2 жыл бұрын
The only firewall I know is Sophos XG and now XGS. I configured HA for a client that is a 24/7 company with 7 warehouses and it was easy and it worked as expected. I have always been intrigued by FortiGate. Which is better?
@salvadorseekatzrisquez2947
@salvadorseekatzrisquez2947 2 жыл бұрын
My experience, is that HA makes the maintenance window longer because the delay after one reboots we need to wait for them to Sync again. Depending on the customer some connections to the Internet will break during HA so for some customer its more outages than less, I am not advocating against redundancy, it's def. nice to have. But a single reboot for upgrade. Maybe Fortinet could improve the way they upgrade. Also I noticed that this on Active/Passive. Active/Active is not really a fact, I have tried to work with Fortinet Support and they have said that it doesn't really work to avoid outages.
@mrStarcKbe
@mrStarcKbe 2 жыл бұрын
True on the A-A part, but not completely true the HA part. You can set it to override disable so it won’t switch back to the primary unit. This way you can initiate it your self. The first failover will always be faster then a single unit. 👍
@billwoodall562
@billwoodall562 2 жыл бұрын
Good video, I do have a question. Can you HA an existing firewall? I have a 201F and bought a backup unit.
@FortinetGuru
@FortinetGuru 2 жыл бұрын
Sure can
@billwoodall562
@billwoodall562 2 жыл бұрын
@@FortinetGuru I am assuming the same process just make the primary firewall the master first?
@ian230187
@ian230187 2 жыл бұрын
Hey...have a doubt here.... Did you get a chance to check the CAM LAN switch where the secondary ports sre connected? They do not populate physical mac address of the Fortigate nic.... wanted to understand the concept
@MladenMarinov
@MladenMarinov 2 жыл бұрын
Hi, I like you lectures. Unfortunately I have problem you did not review - passing the multicast traffic from the provider to STB. Can I contact you to guide me about this?
@dmitriykott769
@dmitriykott769 2 жыл бұрын
Hellow, please make review about new version fortios 7.2!
@zSnowFlakesTV
@zSnowFlakesTV 2 жыл бұрын
Guru, I'm having a really hard time finding a way to build a whitelist in fortiOS 7.0.2, could you make a video talking about white and blacklist rules? how to build it properly? I've been researching reddit and forti cookbock but I just can't figure out what I'm doing wrong. love your videos I learned a lot from you keep it up !!
@pavelbrusnicky2723
@pavelbrusnicky2723 2 жыл бұрын
How about fortigate vs multiple switches session? Thanks.
@hennessy6996
@hennessy6996 2 жыл бұрын
Hi, do you usually do Central NAT? Is your preference Flow-based inspection?
@FortinetGuru
@FortinetGuru 2 жыл бұрын
Majority of my firewalls are done with UTM Profile mode and standard NAT. I have started doing more and more with NGFW Policy mode and Central NAT (especially conversions from PAN devices)
@rosatechnocrat
@rosatechnocrat 2 жыл бұрын
From a working mode or faster traffic Flow mode is better , But in flow mode some the features are not allowed as the in flow mode connection is not terminated on Fortigate. But If you want deep inspection then Proxy mode is better.
@dgilvani
@dgilvani 2 жыл бұрын
Tight! Tight!! TY
@Firecross666
@Firecross666 2 жыл бұрын
Do you have any interest or experience in configuring FortiWeb?
@askmethod
@askmethod 5 ай бұрын
13:03 from where did u bring floating IP
@ashrafhelal9354
@ashrafhelal9354 2 жыл бұрын
13:03 i was wondering, if there isn't a DHCP, how they are going to get a new management IP? and can we do it through cli?
@allferryrocha2698
@allferryrocha2698 2 жыл бұрын
Hey Mike, good time for you to make a video on how to block Log4J on Fortigate FW.
@mrStarcKbe
@mrStarcKbe 2 жыл бұрын
Use IPS signatures and use them as they should be used on “severity” level. So use the IPS filter to block medium,high and critical severity levels. Put them on ALL policy’s! Also on internal once so a breached client can’t use that a signature (medium,high or cricital). For traffic coming from internet use that same IPS filter. And for servers where you can use SSL Server protection put that on too so you can inspect https traffic too.
@salvadorseekatzrisquez2947
@salvadorseekatzrisquez2947 2 жыл бұрын
I like the sound of your keyboard and mouse, what do you use?
@salvadorseekatzrisquez2947
@salvadorseekatzrisquez2947 2 жыл бұрын
8:30
@knithiyanandhan
@knithiyanandhan 2 жыл бұрын
Need a Help: I need to allow port 3306 from outside company one particular IP address?
@shanegreentree7851
@shanegreentree7851 Жыл бұрын
hi. I am looking at buying two 60f, can I use unifi switch to set up ha
@FortinetGuru
@FortinetGuru Жыл бұрын
You can.
@IxTapewormxI
@IxTapewormxI 2 жыл бұрын
Hope your doing alright Chuck its been a few months. Can you show us how to configure a FortiSwitch 224E in Stand alone mode? I've been having issues getting mine to work correctly with the management vlan.
@FortinetGuru
@FortinetGuru 2 жыл бұрын
I am alive, but in the famous words of Big Hero 6....I am not fast.... haha
@renhe108
@renhe108 2 жыл бұрын
Do you consider to set monitor port in HA settings? if the port down, the failover will happen right away.
@FortinetGuru
@FortinetGuru 2 жыл бұрын
That is correct. You would configure monitoring of the port for physical outages. Link monitors will assist if the upstream link is "green" but not passing traffic.
@dirkmare6445
@dirkmare6445 2 жыл бұрын
Hi Mike, new to fortigate fw I recently watched your video about firmware upgrades and your three rules.. I Would really like to use video content filtering but its only included in V7 and not V6.4.6 So I guess my question is for new out of the box setup is it save/advisable to upgrade to newer firmware's and when do you bite the bullet to do upgrades in production? EXAMPLE: GA minus 2 versions Thanks
@rikerud
@rikerud 2 жыл бұрын
What equipment are you running your self this days?
@FortinetGuru
@FortinetGuru 2 жыл бұрын
Still cruising on an 80e-poe at the house
@rikerud
@rikerud 2 жыл бұрын
@@FortinetGuru using Forti AP's with it as well?
@cankitchourasia
@cankitchourasia 3 жыл бұрын
I see you did not select the "Monitor Interface" option under HA. Curious to know how will FWs detect failover scenario.
@FortinetGuru
@FortinetGuru 3 жыл бұрын
Once this foetigate cluster is installed on location I will pick the monitored interfaces based on need. 99% chance I will use the fortilink aggregate and the wan1 port.
@amro_hadi
@amro_hadi 2 жыл бұрын
hey, fortinet Guru, do you have any videos for VDOMs?
@rosatechnocrat
@rosatechnocrat 2 жыл бұрын
What kind of videos you need For Vdoms ..
@amro_hadi
@amro_hadi 2 жыл бұрын
@@rosatechnocrat What are Vdoms for start, what are the use cases when Vdoms can be useful and how the traffic flows in Vdoms.
@abdomordy6935
@abdomordy6935 Жыл бұрын
how can i deploy Fortigate FW HA active-active on AWS in muli AZ environment with autoscalling?
@FortinetGuru
@FortinetGuru Жыл бұрын
Hmmm, good question.
@gastonsalazar5052
@gastonsalazar5052 3 жыл бұрын
gracias Genio!!!
@DhammikaNirodha
@DhammikaNirodha 2 жыл бұрын
Great
@mohamedabdullahi3665
@mohamedabdullahi3665 Жыл бұрын
thanks well legend
@headdstrong983
@headdstrong983 3 жыл бұрын
Hello from Russia. btw recently i configured Fortigate 200 mode with HA mode in prodaction.
@MuhammadWaqas-fq3yg
@MuhammadWaqas-fq3yg 2 жыл бұрын
Can we test the HA Cluster on EVE-NG ? Did any one try it ?
@uneeds2122
@uneeds2122 3 жыл бұрын
Hello Fortinet Guru just one question please I have fortigate which i made web filter on it but some user uses VPN to passthrow web filter how I can fix this, what the method to solve this thank you
@FortinetGuru
@FortinetGuru 3 жыл бұрын
Block vpn access at the application level.
@rodneyaltamera4057
@rodneyaltamera4057 3 жыл бұрын
HI Fortinet Guru I have a question. I have a setup that is in HA Cluster (Active-Active). The problem when I update the firmware both Firewalls will loose connection and restart. I was expecting that the Primary will be updated first, then the backup will be next. Can you give me any advise what I am doing wrong. Thanks
@mrStarcKbe
@mrStarcKbe 2 жыл бұрын
Normally you login on the primary device so the upgrade command is send to the primary device. Then it checks the checksum and if it’s good it will send the update to the secondary device. It them will start updating. In an active/active the load balancing is turned of so all traffic will be route towards primary device.
@frankperera3885
@frankperera3885 2 жыл бұрын
can someone explain how to do the process mentioned in 12:40 ?
@thebocop
@thebocop Жыл бұрын
Confused on how you have this hooked up to the switches...
@FortinetGuru
@FortinetGuru Жыл бұрын
In what way? A of each FortiGate goes to each Switch and B of each FortiGate does the same. Split link on the Fortilink makes it full mesh. Other options are A of each FortiGate to switch 1 and B of each FortiGate to switch 2 with split-fortilink off.
@thebocop
@thebocop Жыл бұрын
@@FortinetGuru I found out I had to delete a few interfaces to make them available for the HA ports on the 60F.... (4 and 5)
@xephael3485
@xephael3485 2 жыл бұрын
1:35 Fortigates use HSRP? Don't use Cisco trash... VRRP, etc.
@ITS-yk5ky
@ITS-yk5ky 5 ай бұрын
The part about the device priority is wrong. The lower the number, the higher the priority.
@FortinetGuru
@FortinetGuru 5 ай бұрын
No. In HA higher priority wins. In routing, lower priority wins.
@raphaelfigueredo5524
@raphaelfigueredo5524 Жыл бұрын
deus do fortinet
@IsmailNuzaifKokky
@IsmailNuzaifKokky 3 жыл бұрын
.
@khalil4826
@khalil4826 2 жыл бұрын
bla bla bla ...
@waqaskhan-cx5dx
@waqaskhan-cx5dx 2 жыл бұрын
I have to two fortigate firwall 201 f and want to configure cluster HA. And Also have to Wan connection. I need a little help with that. Can you please share your email address so we can discuss it sir.
Fortinet: Configuring HA on FortiGate firewalls
10:47
ToThePoint Fortinet
Рет қаралды 34 М.
FortiGate: Application Control (FortiOS 6.4.0)
18:15
Fortinet Guru
Рет қаралды 54 М.
I thought one thing and the truth is something else 😂
00:34
عائلة ابو رعد Abo Raad family
Рет қаралды 10 МЛН
How many people are in the changing room? #devil #lilith #funny #shorts
00:39
How Much Tape To Stop A Lamborghini?
00:15
MrBeast
Рет қаралды 239 МЛН
SIZE DOESN’T MATTER @benjaminjiujitsu
00:46
Natan por Aí
Рет қаралды 4,7 МЛН
DO NOT design your network like this!! // FREE CCNA // EP 6
19:36
NetworkChuck
Рет қаралды 3,3 МЛН
Full Fortinet Stack Environment
27:39
Fortinet Guru
Рет қаралды 68 М.
HA FortiGate Redundant ISP Design and Walk Through
14:31
Fortinet Guru
Рет қаралды 14 М.
FortiGate FortiOS 7.2.4 Walk Through
34:10
Fortinet Guru
Рет қаралды 19 М.
My FortiGate SDWAN Configuration and Some Use Cases
16:25
Fortinet Guru
Рет қаралды 52 М.
InterVlan routing on Fortigate Firewall | Lecture#5
14:51
Doctor Networks
Рет қаралды 54 М.
FortiGate : 5 Admin Access Security Hardening Tips
9:38
Fortinet Guru
Рет қаралды 26 М.
I thought one thing and the truth is something else 😂
00:34
عائلة ابو رعد Abo Raad family
Рет қаралды 10 МЛН