Configuration and operating procedures

Configuring FortiBridge probes

This section describes:

Probe settings

Enabling probes

Verifying that probes are functioning

Tuning the failure threshold and probe interval

Probe settings

Configure probe settings to control the response when a FortiBridge probe detects that the FortiGate unit has failed. Probe settings consist of:

Table 11: Probe settings

Probe Setting

Description

Default

 

 

 

Action on failure

Set the FortiBridge unit response when a probe detects that

fail open

 

the FortiGate unit has failed. The FortiBridge unit can.

 

 

Send alertmail

 

 

Fail open

 

 

Send an SNMP trap

 

 

Send a message to a syslog server

 

 

You can add up to four actions on failure. All of the

 

 

configured actions on failure occur when the FortiBridge

 

 

unit detects a failure.

 

 

 

 

Dynamic IP

Configure the INT 2 and EXT 2 interfaces with dynamic

(none)

pattern

probe IP addresses. The dynamic probe IP addresses

 

 

should not conflict with IP addresses on the network that

 

 

the FortiGate unit is connected to. These IP addresses are

 

 

not visible from the outside network, but they should not

 

 

conflict with IP addresses in packets passing through the

 

 

FortiBridge unit. You cannot change the dynamic IP pattern

 

 

if any probes are enabled.

 

 

 

 

FortiGate unit

The serial number of the FortiGate unit that the FortiBridge

(none)

serial number

unit is connected to. The serial number appears in

 

 

FortiBridge alert mail, and syslog messages to identify the

 

 

FortiGate unit.

 

 

 

 

 

To configure probe settings

This procedure shows how to configure the following probe settings:

The FortiBridge unit responds to a FortiGate unit failure by failing open and by sending an alert email, a syslog message, and an SNMP trap

The dynamic IP pattern is 2.2.2.*

The FortiGate unit serial number is FGT8002803923050

Note: The FortiBridge unit does not have to fail open if the FortiGate unit fails. The

FortiBridge unit can be configured just to send alerts if the FortiGate unit fails.

1Log in to the FortiBridge CLI.

FortiBridge Version 3.0 Administration Guide

37

09-30000-0163-20061109

Page 37
Image 37
Fortinet Version 3.0 manual Probe settings, To configure probe settings