HA in Transparent mode

High availability

 

 

7If you are configuring Active-Active HA, select a schedule.

The schedule controls load balancing among the FortiGate units in the active-active HA cluster. The schedule must be the same for all FortiGate units in the HA cluster.

None

No load balancing. Select None when the cluster interfaces are

 

connected to load balancing switches.

Hub

Load balancing for hubs. Select Hub if the cluster interfaces are

 

connected to a hub. Traffic is distributed to units in a cluster based on

 

the Source IP and Destination IP of the packet.

Least Connection

Least connection load balancing. If the FortiGate units are connected

 

using switches, select Least connection to distribute traffic to the cluster

 

unit with the fewest concurrent connections.

Round Robin

Round robin load balancing. If the FortiGate units are connected using

 

switches, select round robin to distribute traffic to the next available

 

cluster unit.

Weighted Round Robin

Weighted round robin load balancing. Similar to round robin, but weighted values are assigned to each of the units in a cluster based on their capacity and on how many connections they are currently processing. For example, the primary unit should have a lower weighted value because it handles scheduling and forwards traffic. Weighted round robin distributes traffic more evenly because units that are not processing traffic will be more likely to receive new connections than units that are very busy.

Random

Random load balancing. If the FortiGate units are connected using

 

switches, select random to randomly distribute traffic to cluster units.

IP

Load balancing according to IP address. If the FortiGate units are

 

connected using switches, select IP to distribute traffic to units in a

 

cluster based on the Source IP and Destination IP of the packet.

IP Port

Load balancing according to IP address and port. If the FortiGate units

 

are connected using switches, select IP Port to distribute traffic to units

 

in a cluster based on the Source IP, Source Port, Destination IP, and

 

Destination port of the packet.

8Under Monitor on Interface, select the names of the interfaces to be monitored.

Monitor FortiGate interfaces to make sure they are functioning properly and that they are connected to their networks. If a monitored interface fails or is disconnected from its network, the FortiGate unit stops processing traffic and is removed from the cluster. If you can re-establish traffic flow through the interface (for example, if you re-connect a disconnected network cable) the FortiGate unit rejoins the cluster. You should only monitor interfaces that are connected to networks.

9Select Apply.

The FortiGate unit negotiates to establish an HA cluster. When you select apply you may temporarily loose connectivity with the FortiGate unit as the HA cluster negotiates.

84

Fortinet Inc.

Page 84
Image 84
Fortinet 400 manual None