Configuring FortiGate units for HA operation |
| High availability installation | |
|
|
|
|
| Table 10: High availability settings | ||
|
|
|
|
|
| Load balancing and failover HA. Each FortiGate unit in the | |
|
|
| HA cluster actively processes connections and monitors the |
|
|
| status of the other FortiGate units in the cluster. The |
|
|
| primary FortiGate unit in the cluster controls load balancing. |
| Mode |
|
|
| Failover HA. The primary FortiGate unit in the cluster | ||
|
|
| processes all connections. All other FortiGate units in the |
|
|
| cluster are passively monitor the cluster status and remain |
|
|
| synchronized with the primary FortiGate unit. |
|
|
|
|
|
| All members of | the HA cluster must be set to the same HA mode. |
|
|
| |
|
| The group ID range is from 0 to 63. All members of the HA cluster must have | |
|
| the same group ID. | |
|
| When the FortiGate units in the cluster are switched to HA mode, all of the | |
|
| interfaces of all of the units in the cluster get the same virtual MAC address. | |
|
| This virtual MAC address is set according to the group ID. | |
|
|
|
|
|
| Group ID | MAC Address |
|
|
|
|
|
| 0 | |
|
|
|
|
| Group ID | 1 | |
|
|
| |
| 2 | ||
|
| ||
|
|
|
|
|
| 3 | |
|
|
|
|
|
| … |
|
|
|
|
|
|
| 63 | |
|
|
|
|
|
| If you have more | than one HA cluster on the same network, each cluster |
|
| should have a different group ID. If two clusters on the same network have | |
|
| same group ID, the duplicate MAC addresses cause addressing conflicts on | |
|
| the network. |
|
|
|
| |
|
| The unit with the highest priority becomes the primary unit in the cluster. The | |
|
| unit priority range is 0 to 255. The default unit priority is 128. | |
| Unit priority | Set the unit priority to a higher value if you want the FortiGate unit to be the | |
| primary cluster unit. Set the unit priority to a lower value if you want the | ||
|
| FortiGate unit to be a subordinate unit in the cluster. If all units have the | |
|
| same priority, the FortiGate unit with the highest serial number becomes the | |
|
| primary cluster unit. | |
|
|
| |
| Override | You can configure a FortiGate unit to always become the primary unit in the | |
| Master | cluster by giving it a high priority and by selecting Override master. | |
|
|
|
|
48 | Fortinet Inc. |