Ha Configuration - Fortinet FortiGate FortiGate-5001 Administration Manual

Fortigate 5000 series
Hide thumbs Also See for FortiGate FortiGate-5001:
Table of Contents

Advertisement

HA

HA configuration

92
By default a FortiGate HA active-active cluster load balances virus scanning sessions
among all cluster units. All other traffic is processed by the primary unit. Using the CLI,
you can configure the cluster to load balance all network traffic among all cluster units.
See
"To switch between load balancing virus scanning sessions and all sessions" on
page
102.
For more information about FortiGate HA and the FGCP, see the
Availability Guide
and the
FortiGate HA compatibility with DHCP and PPPoE
FortiGate HA is not compatible with PPP protocols such as DHCP or PPPoE. If one or
more FortiGate unit interfaces is dynamically configured using DHCP or PPPoE you
cannot switch to operating in HA mode. Also, if you are operating a FortiGate HA
cluster, you cannot change a FortiGate interface in the cluster to be configured
dynamically using DHCP or PPPoE.
Configuring a FortiGate interface to be a DHCP server or a DHCP relay agent is not
affect by HA operation. For information about DHCP server and relay, see
DHCP" on page
79.
PPTP and L2TP are supported in HA mode. You can configure PPTP and L2TP
settings (see
"PPTP range" on page 270
add firewall policies to allow PPTP and L2TP pass through. However, during an HA
failover event, any active PPTP and L2TP sessions are lost and must be restarted
after the failover.
Go to System > Config > HA and use the options described below to configure HA.
Standalone Mode
High Availability
Cluster Members
Mode
Group ID
Unit Priority
Override Master
Password
Schedule
Priorities of Heartbeat Device
Heartbeat device IP addresses
Monitor priorities
01-28008-0013-20050204
Fortinet Knowledge
Center.
and
"L2TP range" on page
System Config
FortiGate High
"System
271) you can also
Fortinet Inc.

Advertisement

Table of Contents
loading

Table of Contents