FortiGate-400 Installation and Configuration Guide Version 2.50 MR2
FortiGate-400 Installation and Configuration Guide 75
High availability
Fortinet achieves high availability (HA) using redundant hardware and the FortiGate
Clustering Protocol (FGCP). The FortiGate units in the HA cluster enforce the same
overall security policy and share the same configuration settings. You can add up to
32 FortiGate units to an HA cluster. Each FortiGate unit in an HA cluster must be the
same model and be running the same FortiOS firmware image.
FortiGate HA is device redundant. If one of the FortiGate units in an HA cluster fails,
all functions, all established firewall connections, and all IPSec VPN sessions1 are
maintained by the other FortiGate units in the HA cluster.
The FortiGate units in the cluster use dedicated HA ethernet interfaces to
communicate cluster session information and report individual system status. The
units in the cluster are constantly communicating HA status information to make sure
the cluster is functioning properly. For this reason, the connection between the HA
ports of all of the FortiGate units in the cluster must be well maintained. An interruption
of this communication can cause unpredictable results.
You can manage the cluster by connecting to any cluster interface configured for
management access.
FortiGate units can be configured to operate in active-passive (A-P) or active-active
(A-A) HA mode. Active-active and active-passive HA are supported in both NAT/Route
and Transparent modes.
This chapter provides an overview of HA functionality and describes how to configure
and manage HA clusters in NAT/Route mode and in Transparent mode.
Active-passive HA
Active-active HA
HA in NAT/Route mode
HA in Transparent mode
Managing the HA cluster
Advanced HA options

Active-passive HA

An Active-passive (A-P) HA cluster, also referred to as hot standby HA, consists of a
primary FortiGate unit that is processing traffic and one or more subordinate FortiGate
units connected to the network and to the primary FortiGate unit but not processing
traffic.
1.HA does not provide session failover for PPPoE, DHCP, PPTP, and L2TP services.