HA configuration

System config

 

 

Schedule

If you are configuring an active-active cluster, select a load balancing schedule.

None

No load balancing. Select None when the cluster interfaces are connected

 

to load balancing switches.

Hub

Load balancing if the cluster interfaces are connected to a hub. Traffic is

 

distributed to cluster units based on the Source IP and Destination IP of the

 

packet.

Least-

Least connection load balancing. If the cluster units are connected using

Connection

switches, select Least Connection to distribute network traffic to the cluster

 

unit currently processing the fewest connections.

Round-Robin

Round robin load balancing. If the cluster units are connected using

 

switches, select Round-Robin to distribute network traffic to the next

 

available cluster unit.

Weighted Round-Robin

Weighted round robin load balancing. Similar to round robin, but weighted values are assigned to each of the units in a cluster based on their capacity and on how many connections they are currently processing. For example, the primary unit should have a lower weighted value because it handles scheduling and forwards traffic. Weighted round robin distributes traffic more evenly because units that are not processing traffic will be more likely to receive new connections than units that are very busy.

Random

Random load balancing. If the cluster units are connected using switches,

 

select Random to randomly distribute traffic to cluster units.

IP

Load balancing according to IP address. If the cluster units are connected

 

using switches, select IP to distribute traffic to units in a cluster based on the

 

Source IP and Destination IP of the packet.

IP Port

Load balancing according to IP address and port. If the cluster units are

 

connected using switches, select IP Port to distribute traffic to units in a

 

cluster based on the source IP, source port, destination IP, and destination

 

port of the packet.

Priorities of Heartbeat Device

Enable or disable HA heartbeat communication and set the heartbeat priority for each interface in the cluster.

By default HA heartbeat communication is set for two interfaces. You can disable HA heartbeat communication for either of these interfaces or enable HA heartbeat for other interfaces. In most cases you can maintain the default heartbeat device configuration as long as you can connect the heartbeat device interfaces together.

To enable HA heartbeat communication for an interface, enter a priority for the interface. To disable HA heartbeat communication for an interface, delete the priority for the interface.

The HA heartbeat priority range is 0 to 512. The interface with the highest priority handles all HA heartbeat traffic. If this interface fails or becomes disconnected, the interface with the next highest priority handles all HA heartbeat traffic.

The cluster units use the ethernet interfaces configured with HA heartbeat priorities for HA heartbeat communication. The HA heartbeat communicates cluster session information, synchronizes the cluster configuration, synchronizes the cluster routing table, and reports individual cluster member status. The HA heartbeat constantly communicates HA status information to make sure that the cluster is operating properly.

88

01-28007-0068-20041203

Fortinet Inc.

Page 88
Image 88
Fortinet 100A manual Schedule, Priorities of Heartbeat Device

100A specifications

Fortinet 100A is a versatile network security device designed to provide comprehensive protection against various cyber threats while ensuring optimal network performance. As part of the FortiGate series, the 100A combines advanced security features with powerful hardware capabilities, making it suitable for small to medium-sized businesses.

One of the key features of the Fortinet 100A is its deep packet inspection technology. This capability allows the firewall to analyze both the header and payload of packets traversing the network, enabling it to detect and block malicious content effectively. The 100A can identify and mitigate a wide range of threats, including malware, intrusions, and application-layer attacks.

The FortiOS operating system powers the Fortinet 100A, offering a robust and user-friendly interface for configuration and management. With its unified security management console, administrators can efficiently monitor network traffic and enforce security policies across the organization. The system provides centralized logging and reporting features, enabling users to gain valuable insights into their security posture and respond swiftly to incidents.

The 100A supports multiple deployment modes, including transparent, NAT, and route modes. This flexibility allows organizations to integrate the device into their existing network architecture with ease. The firewall's high throughput capabilities ensure that network performance remains unaffected, even under heavy load from multiple users and devices.

Another notable aspect of the Fortinet 100A is its support for various VPN technologies, including IPsec and SSL VPN. This feature facilitates secure remote access for employees, enabling them to connect to the corporate network safely, regardless of their location. As remote work continues to be a norm in many sectors, this capability is critical for maintaining productivity and security.

In addition to these features, the Fortinet 100A provides comprehensive web filtering capabilities, protecting users from harmful websites and inappropriate content. This protection is essential for organizations looking to maintain a secure and productive environment.

With its combination of powerful security features, flexible deployment options, and robust performance, the Fortinet 100A stands out as an ideal solution for organizations seeking to bolster their cybersecurity measures while ensuring seamless connectivity for users. As cyber threats continue to evolve, investing in a capable device like the FortiGate 100A is crucial for maintaining a secure network infrastructure.