No video

How to Configure High Availability (HA) Fortigate Cluster

  Рет қаралды 34,921

ElastiCourse

ElastiCourse

Күн бұрын

Пікірлер: 25
@gullitlevia787
@gullitlevia787 3 ай бұрын
Hi Instructor, do you have a video on how to upgrade FortiOS on a HA Fortigate Cluster. If not, can you please make one or direct to a resource
@patz007
@patz007 3 жыл бұрын
I learned something new! Thanks a lot!
@jinoosvictory6464
@jinoosvictory6464 2 жыл бұрын
Thanks for sharing your knowledge. two questions:1-Mostly there are two different ISPs connected to master and backup firewall imagine master is connected to ISP1 and backup is connected to ISP2 then how does it work? and what would be IP address of port1(wan interface) 2-what would be happen to IPsec and VPNs when master firewall goes down?
@mdabdulmoiz
@mdabdulmoiz 2 жыл бұрын
you don't like the sd-wan feature?
@ElastiCourse
@ElastiCourse 2 жыл бұрын
Very good question Jinoos. IPSec VPN is usually hardcoded to one static IP address or DNS name, and remote gateway can't be used in multiple VPNs - limit one - so your best option in this case as Abdul mentioned is to create SD-WAN zone (check channel latest video on how to configure SD-WAN), include WAN1 and WAN2 interfaces to an SD-WAN zone, create default route to SD-WAN zone interface instead of individual port names. Create VPN tunnel, local interface should be the SD-WAN zone, and firewall policies according o your needs, now your side is done. For the remote site they need to be able to connect to either of your public IPs, the hard way to do this is to have them create two tunnels with same settings except one of them has remote gateway your Public IP 1 and the other would have remote gateway as Public IP 2, the easy way to do this is to enable FortiGuard DDNS on the settings page, this will assign your SD-WAN interface IP to a domain like jinoos.fortiddns.com then ask them to create one tunnel only with remote gateway set as Dynamic DNS and the hostname would be jinoos.fortiddns.com, only caveat for the easy method if you watch the SD-WAN video you will notice lots of failovers and these DNS changes on Internet take time to take effect so might cause downtimes occasionally. Go for hard way for more stability.
@fellaoulounis8491
@fellaoulounis8491 2 жыл бұрын
Thanks for sharing your knowledge, i have one question h,can you please send me a switch configration between a switch and two fotigate ?, thank you
@ElastiCourse
@ElastiCourse 2 жыл бұрын
Hi Fella, what kind of switch are you using and what are you trying to configure on it? for heartbeat links they can be connected directly between two firewalls or through a switch but since it's layer2 communication no need to configure anything on switch side.
@aidilsyar
@aidilsyar 2 жыл бұрын
for the "Switch1" configuration, does it need to configure LAG/LACP for Port "e0" and Port "e1"??.. based on my understanding for this design look does not need do any configuration on the switch because it Active-Passive mode.. i believe for ACTIVE-ACTIVE mode required to configure LACP
@ElastiCourse
@ElastiCourse 2 жыл бұрын
LACP is not needed at all for this example, the switch would forward the ARP requests and primary firewall would answer with its virtual mac address, switch then will learn to use that interface (until ARP time out) to reach the upstream gateway.
@mdabdulmoiz
@mdabdulmoiz 2 жыл бұрын
One question here is since there is only one link between the two firewalls is this the only link responsible for sharing Heartbeat, Link down info, session table information and config changes replication? don't we use two links as we do with the Palo Alto Control link and Data links?
@ElastiCourse
@ElastiCourse 2 жыл бұрын
You can configure multiple HA links for redundancy which is quite common on enterprise networks, Assume you dedicate ports 10 and 11 for HA redundant links you would complete the config as follows config system ha set hbdev port10 100 port11 75 end The HB device refers to heartbeat interfaces used to communicate cluster info via multicast. The following numbers (100 and 75) are heartbeat interface priority, higher priority means more preferred, so in above example port10 with higher priority is used and preferred unless it goes down or fail, then switch to port11 and continue cluster sync.
@malikpj5254
@malikpj5254 3 жыл бұрын
thanks for sharing, i have one question here, once the second device is joining to the cluster, is there any restart/reboot on the 1st device or 2nd device, or even both device?
@ElastiCourse
@ElastiCourse 3 жыл бұрын
No restart needed. Use (diag sys ha status) to verify both members status are in-sync
@malikpj5254
@malikpj5254 3 жыл бұрын
@@ElastiCourse thank you, do you have HA in active active video?
@ElastiCourse
@ElastiCourse 3 жыл бұрын
Not currently, but I will work on HA Active Active setup soon.
@malikpj5254
@malikpj5254 3 жыл бұрын
@@ElastiCourse sounds great, i can't wait for it :D
@mohmaedhajithmohmaedhajith4782
@mohmaedhajithmohmaedhajith4782 2 жыл бұрын
In active active mode like load balancing is it right???
@ElastiCourse
@ElastiCourse 2 жыл бұрын
Correct Active-Active is more ideal for higher bandwidth, and it shares same capabilities of Active Passive setup like automatic session failover and two-way config sync.
@mohmaedhajithmohmaedhajith4782
@mohmaedhajithmohmaedhajith4782 2 жыл бұрын
Please share the cli command it's useful for our practice CLI mode
@ElastiCourse
@ElastiCourse 2 жыл бұрын
config system ha set mode a-a end This is the command to convert to Active-Active mode
@mohmaedhajithmohmaedhajith4782
@mohmaedhajithmohmaedhajith4782 2 жыл бұрын
No. Am asking like documentation it's useful for us.. If you any blog please share me.
@balla2172
@balla2172 3 жыл бұрын
Can u not do it via gui
@ElastiCourse
@ElastiCourse 3 жыл бұрын
You can configure HA using GUI or CLI. CLI is better in my opinion as it shows more hidden options. Try this to see yourself the amount of hidden options: config system ha set ? Question mark will list all options possible for HA config also: config system ha config ?
@ElastiCourse
@ElastiCourse 4 жыл бұрын
This video is part of Introduction to Fortigate Firewall course, get it now on ElastiCourse/Udemy: www.elasticourse.com/courses/introduction-to-fortigate-firewall/ www.udemy.com/course/introduction-to-fortigate-firewall/?referralCode=AA76B8B95B4D27DCD75C
@patz007
@patz007 3 жыл бұрын
May i kindly ask if the course posted on udemy is good enough to get pass NSE4 or other levels?
FortiGate 60F HA Cluster Build
22:25
Fortinet Guru
Рет қаралды 51 М.
If Barbie came to life! 💝
00:37
Meow-some! Reacts
Рет қаралды 75 МЛН
Fortunately, Ultraman protects me  #shorts #ultraman #ultramantiga #liveaction
00:10
Meet the one boy from the Ronaldo edit in India
00:30
Younes Zarou
Рет қаралды 18 МЛН
How to configure SD-WAN on Fortigate
28:40
ElastiCourse
Рет қаралды 39 М.
21. FortiGate 6.0 High Availability HA Best Practices
29:32
Devin Adams
Рет қаралды 24 М.
How to create Virtual Domains or VDOMs on Fortigate Firewall
11:09
ElastiCourse
Рет қаралды 31 М.
Fortinet: Configuring HA on FortiGate firewalls
10:47
ToThePoint Fortinet
Рет қаралды 30 М.
PostgreSQL HA High Availability Tutorial
19:04
High-Performance Programming
Рет қаралды 46 М.
Low Power Cluster - Small, Efficient, BUT Powerful!
12:18
Techno Tim
Рет қаралды 179 М.
FortiGate High Availability Active Passive Configuration
22:32
Inquirinity
Рет қаралды 4,8 М.
If Barbie came to life! 💝
00:37
Meow-some! Reacts
Рет қаралды 75 МЛН