Connecting the cluster to your networks | High availability installation |
|
|
Inserting an HA cluster into your network temporarily interrupts communications on the network because new physical connections are being made to route traffic through the cluster. Also, starting the cluster interrupts network traffic until the individual FortiGate units in the cluster are functioning and the cluster completes negotiation. Cluster negotiation normally takes just a few seconds. During system startup and negotiation all network traffic is dropped.
To connect the cluster
1Connect the cluster units:
•Connect the internal interfaces of each FortiGate unit to a switch or hub connected to your internal network.
•Connect the WAN1 interfaces of each FortiGate unit to a switch or hub connected to your external network.
•Connect the DMZ interfaces of the FortiGate units to another switch or hub. By default the DMZ interfaces are used for HA heartbeat communications. These interfaces should be connected together for the HA cluster to function.
•Optionally connect the WAN2 interface of each FortiGate unit to a switch or hub connected a second external network.
Figure 12: HA network configuration
Internal Network
Internal WAN1
|
|
| INTERNAL |
|
|
|
| |
PWR | STATUS | 1 | 2 | 3 | 4 | DMZ | WAN1 | WAN2 |
|
| LINK 100 | LINK 100 | LINK 100 | LINK 100 | LINK 100 | LINK 100 | LINK 100 |
Hub or |
|
|
|
| DMZ | Hub or | |||
Switch |
|
|
|
|
|
|
|
| Switch |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
DMZ
|
|
| INTERNAL |
|
|
|
| |
PWR | STATUS | 1 | 2 | 3 | 4 | DMZ | WAN1 | WAN2 |
|
| LINK 100 | LINK 100 | LINK 100 | LINK 100 | LINK 100 | LINK 100 | LINK 100 |
Router
Internal WAN1
Internet
52 | Fortinet Inc. |