Configuration Synchronization - Fortinet FortiGate-7060E Handbook

Fortios
Hide thumbs Also See for FortiGate-7060E:
Table of Contents

Advertisement

Configuration synchronization

set protocol icmp
set comment "icmp"
next
edit 31
set status enable
set ether-type ipv6
set protocol icmpv6
set comment "icmpv6"
next
edit 32
set ether-type ipv6
set protocol 41
end
Configuration synchronization
The FortiGate-7000 synchronizes the configuration to all modules in the chassis. To support this feature, the
interface module in slot 1 becomes the config-sync master and this module makes sure the configurations of all
modules are synchronized. Every time you make a configuration change you must be logged into the chassis
using the management address, which logs you into the config-sync master. All configuration changes made to
the config-sync master are synchronized to all of the modules in the chassis.
If the FIM module in slot 1 fails or reboots, the FIM module in slot 2 becomes the config-sync master.
Failover in a standalone FortiGate-7000
A FortiGate-7000 will continue to operate even if one of the FIM or FPM modules fails or is removed. If an FPM
module fails, sessions being processed by that module fail. All sessions are then load balanced to the remaining
FPM modules. Sessions that were being processed by the failed module are restarted and load balanced to the
remaining FPM modules.
If an FIM module fails, the other FIM module will continue to operate and will become the config-sync master.
However, traffic received by the failed FIM module will be lost.
You can use LACP or redundant interfaces to connect interfaces of both FIMs to the same network. In this way, if
one of the FIMs fails the traffic will continue to be received by the other FIM module.
Replacing a failed FPM or FIM module
This section describes how to remove a failed FPM or FIM module and replace it with a new one. The procedure
is slightly different depending on if you are operating in HA mode with two chassis or just operating a standalone
chassis.
Replacing a failed module in a standalone FortiGate-7000 chassis
1. Power down the failed module by pressing the front panel power button.
2. Remove the module from the chassis.
3. Insert the replacement module. It should power up when inserted into the chassis if the chassis has power.
39
Getting started with FortiGate-7000
FortiGate-7000
Fortinet Technologies Inc.

Advertisement

Table of Contents
loading

Table of Contents