Interface Status Detection For Gateway Load Balancing - Fortinet FortiGate Series Administration Manual

Hide thumbs Also See for FortiGate Series:
Table of Contents

Advertisement

System Network

Interface status detection for gateway load balancing

FortiGate Version 4.0 MR1 Administration Guide
01-410-89802-20090903
http://docs.fortinet.com/
Feedback
To improve the security of a FortiGate unit that allows remote administration from the
Internet:
Use secure administrative user passwords.
Change these passwords regularly.
Enable secure administrative access to this interface using only HTTPS or SSH.
Do not change the system idle timeout from the default value of 5 minutes (see
"Settings" on page
286).
For more information on configuring administrative access in Transparent mode, see
"Operation mode and VDOM management access" on page
To control administrative access to an interface
1 Go to System > Network > Interface.
2 Choose an interface and select Edit.
3 Select the Administrative Access methods for the interface.
4 Select OK.
You can use up to three different protocols to confirm that an interface can connect to the
IP address of a server. Usually the server is the next-hop router that leads to an external
network or the Internet. Interface status detection is available if ECMP Route Failover &
Load Balance Method is set to spill-over. See
To configure gateway failover detection for an interface, from the web-based manager go
to System > Network > Interface and edit an interface. Select Detect Interface Status for
Gateway Load Balancing, enter the IP address of the server to test connecting to and
select one or more protocols to use to test the connection to the server.
Go
System > Network > Options
detection settings for interface status detection. See
page
204.
Note: As long as the FortiGate unit receives responses for at least one of the protocols that
you select the FortiGate unit assumes the server is operating and can forward packets.
Responses received to more protocols does not enhance the status of the server or
interface and receiving response from fewer protocols does not reduce the status of the
server or interface.
263.
to configure the detection interval and failover
"Configuring Networking Options" on
Configuring interfaces
193

Advertisement

Table of Contents
loading

Table of Contents