Connecting the cluster to your networks

High availability installation

 

 

Inserting an HA cluster into your network temporarily interrupts communications on the network because new physical connections are being made to route traffic through the cluster. Also, starting the cluster interrupts network traffic until the individual FortiGate units in the cluster are functioning and the cluster completes negotiation. Cluster negotiation normally takes just a few seconds. During system startup and negotiation all network traffic is dropped.

To connect the cluster

1Connect the cluster units:

Connect the internal interfaces of each FortiGate unit to a switch or hub connected to your internal network.

Connect the WAN1 interfaces of each FortiGate unit to a switch or hub connected to your external network.

Connect the DMZ interfaces of the FortiGate units to another switch or hub. By default the DMZ interfaces are used for HA heartbeat communications. These interfaces should be connected together for the HA cluster to function.

Optionally connect the WAN2 interface of each FortiGate unit to a switch or hub connected a second external network.

Figure 12: HA network configuration

Internal Network

Internal WAN1

 

 

 

INTERNAL

 

 

 

 

PWR

STATUS

1

2

3

4

DMZ

WAN1

WAN2

 

 

LINK 100

LINK 100

LINK 100

LINK 100

LINK 100

LINK 100

LINK 100

Hub or

 

 

 

 

DMZ

Hub or

Switch

 

 

 

 

 

 

 

 

Switch

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

DMZ

 

 

 

INTERNAL

 

 

 

 

PWR

STATUS

1

2

3

4

DMZ

WAN1

WAN2

 

 

LINK 100

LINK 100

LINK 100

LINK 100

LINK 100

LINK 100

LINK 100

Router

Internal WAN1

Internet

52

01-28008-0018-20050128

Fortinet Inc.

Page 52
Image 52
Fortinet MR8 manual To connect the cluster, HA network configuration