How to Deploy SDN-HA FortiGate VM in Azure [FortiGate and Fabric Connector Setup]

  Рет қаралды 6,733

NetQuiet

NetQuiet

2 жыл бұрын

Hello Engineers and Admins,
In this video we will configure a High Availability FortiGate in Azure using a Fabric Connector or SDN.
We will be recreating this common topology referenced in the knowledge base below:
docs.fortinet.com/document/fo...
github.com/fortinet/azure-tem...
For more fun tips and tricks please visit our website for blogs, videos, and more!
netquiet.com/

Пікірлер: 15
@goodupandit3640
@goodupandit3640 2 жыл бұрын
I've never seen a video this beneficial before.
@jasonredwine2916
@jasonredwine2916 Жыл бұрын
Best video I have seen of this yet! Both MS and FGT support sent me links to some craziness, but this was clear and concise, but, mostly, EXACTLY what MS/FGT should have produced. Thanks for doing their work! A+ video!
@13Anant
@13Anant Жыл бұрын
Concise and to the point. I've always used ILB/ELB for HA in Azure but it turns out the Fabric Connector is a much more efficient way of managing HA and failover. Thanks heaps :)
@williamgregoire5090
@williamgregoire5090 Жыл бұрын
Do you know any benefits of using additional Load Balancer?
@13Anant
@13Anant Жыл бұрын
@@williamgregoire5090 Not a lot that I can think of. With separately managed LB, you only provision one Public IP address resource for the HA stack and the load balancer monitors the backend Fortigate VMs to determine which of the two HA members the public IP address should be assigned to. It works just as fine as a Fabric connector failover but with Fabric connector approach, at least I'm not managing and paying for Internal and external load balancers.
@williamgregoire
@williamgregoire Жыл бұрын
Great, thank you!
@EyeIn_The_Sky
@EyeIn_The_Sky 2 жыл бұрын
I wish you would do a tutorial showing a similar HA setup but with External and Internal Load balancers involved :/
@aminderpuri640
@aminderpuri640 2 жыл бұрын
that would be great, just what I am looking for
@nemanjaserafimovic9939
@nemanjaserafimovic9939 Жыл бұрын
Thanks for this video! The best explanation of this scenario I've ever seen! Could you please cover the Active - Active scenario with Load Balancers as well?
@ashokfaujdar6367
@ashokfaujdar6367 Жыл бұрын
Really helpful information and i did the similar config as you demonstrated, thanks man !
@aminderpuri640
@aminderpuri640 2 жыл бұрын
Hi, I was wondering what you need to do to get the fortigate to update other routes you may have in the routing table when switching over to the secondary firewall?
@williamgregoire5090
@williamgregoire5090 Жыл бұрын
Is there any advantage of implementing Active/Pasive with ILB/ELB over this model with the Fabric Connector? After seeing this video I don't see any (it costs more, and I have more components to manage with additional LoadBalancers)? Thank you for your help and great video
@princeboothe9200
@princeboothe9200 2 жыл бұрын
If a Single VM for Fortigate was deployed and I want to add another Fortigate to create HA, can I use the marketplace or do I use the ARM template?
@SpacezCowboy
@SpacezCowboy 2 жыл бұрын
Ever find out a method for doing this? I'm contemplating the same for an existing subscription. It's a debate between add a fortigate and do this all manually or use the template and move vm's to the new production subnet.
@joerivanhoof5820
@joerivanhoof5820 Жыл бұрын
The easiest is to deploy a cluster next to the existing single VM and import the config into the cluster so you can test before migration. With UDRs you can move just a single subnet to the new setup. Migrating would mean you need to have the single FGT in an Availability Set or you need to move the VM into a zone. The latest Single VM templates allow you to add a FortiGate VM into an existing AV Set or AV Zone. Secondly you need to add extra network interfaces for the HA Sync and HA mgmt. Also if you are using Basic SKU public IPs I would move them to Standard SKU IPs and use the FortiGate Active/Passive ELB/ILB setup. Faster failover and less overhead in configuring routetable sync in the SDN connector.
No One Wants To Be A Network Engineer Anymore
21:44
Gestalt IT
Рет қаралды 71 М.
Советы на всё лето 4 @postworkllc
00:23
История одного вокалиста
Рет қаралды 4,6 МЛН
لااا! هذه البرتقالة مزعجة جدًا #قصير
00:15
One More Arabic
Рет қаралды 20 МЛН
FortiGate 60F HA Cluster Build
22:25
Fortinet Guru
Рет қаралды 50 М.
Deep Inspection on FortiGate firewall with 5 Examples
21:38
ToThePoint Fortinet
Рет қаралды 19 М.
How to Deploy Single Palo Alto VM in Azure [Palo Alto Part 2]
16:31
How to Deploy Single Palo Alto VM in Azure [Palo Alto Set Up]
22:29
How I Would Learn To Code (If I Could Start Over)
13:43
Namanh Kapur
Рет қаралды 7 МЛН
Azure Routing explained in plain English with a story in 10 mins-User Defined Routes, Route priority
12:04
Arm PC Build (Rock 5 ITX)
22:35
ExplainingComputers
Рет қаралды 93 М.
Nokia 3310 top
0:20
YT 𝒯𝒾𝓂𝓉𝒾𝓀
Рет қаралды 4,3 МЛН
Частая ошибка геймеров? 😐 Dareu A710X
1:00
Вэйми
Рет қаралды 5 МЛН
Rate This Smartphone Cooler Set-up ⭐
0:10
Shakeuptech
Рет қаралды 7 МЛН
Xiaomi SU-7 Max 2024 - Самый быстрый мобильник
32:11
Клубный сервис
Рет қаралды 553 М.
Опасность фирменной зарядки Apple
0:57
SuperCrastan
Рет қаралды 12 МЛН