Next Generation Firewall (NGFW)

Expand all | Collapse all

HA additional port

  • 1.  HA additional port

    Posted Jun 24, 2020 02:36 AM
    ​​Hello guys,

    I am a beginner on Fortigate. I have a question about the HA port.
    Is it possible to configure two HA ports on each Forti 200E to create a Active/Passive cluster? I saw only one HA port on the Datasheet.
    Thank you very much.

    Regards.


  • 2.  RE: HA additional port

    Posted Jun 24, 2020 02:39 AM
    Hi hien,
    Yes, you can configure 1/2/3... HA ports in A/A or A/P cluster.


    ------------------------------
    Faridul
    ------------------------------



  • 3.  RE: HA additional port

    Posted Jun 24, 2020 02:50 AM
    Hi Faridul,

    Thank you for your quick response.

    So if I use port1, port2 for HA connections, this HA port will be unused. Am I right?

    Is this HA port dedicated only for HA? Can I use it for other purpose?​


  • 4.  RE: HA additional port

    Posted Jun 24, 2020 03:03 AM
    Hi hien,
    Depending on Firewall model, there might be 1/2 dedicated HA port(s), but you can use any physical port as HA port(s).
    But, never use any logical port in HA, like: Software Switch port(s), Hardware Switch port(s), Redundant/Aggregation port(s)...etc.

    In FortiGate:
    1. Any ports can be data ports.
    2. Any HA ports can be data ports.
    3. You can convert any dedicated management (OOB > Out-of-Band Management) ports to data ports.
    4. Yes, in FGT - You can do the combination of dedicated HA port and regular data port as HA ports.




    ------------------------------
    Faridul
    ------------------------------



  • 5.  RE: HA additional port

    Posted Jun 24, 2020 02:53 AM
    Dear Hien,

    The answer to your question is YES!

    You can assign another port as HA to the dedicated HA port. With this, you will leverage on configuration  and session synchronization of the cluster


  • 6.  RE: HA additional port

    Posted Jun 24, 2020 03:01 AM
    Hi Shadrack,

    In order to give the max port occupation, may I configure like this:
    HA port and port1 (for example) for the cluster?​


  • 7.  RE: HA additional port

    Posted Jun 24, 2020 03:07 AM
    Yes, in FGT - You can do the combination of dedicated HA port and regular data port as HA ports

    ------------------------------
    Faridul
    ------------------------------



  • 8.  RE: HA additional port

    Posted Jun 24, 2020 03:13 AM
    Thank you all of you guys.

    I got it. So Fortigate is very flexible and simple about configuration.​


  • 9.  RE: HA additional port

    Posted Jun 24, 2020 03:12 AM
    Yes Sure!

    Go ahead and select  the dedicated HA port and port1 under Heatbeat interfaces for your High Availability Setup.