FORTIGATE HA AND VIRTUAL CLUSTER CONFIGURATION In this document we describe how to cluster two Fortigate devices and then make virtualization in this cluster with VDOMS and then making virtual cluster to load balance traffic between two deferent instances of devices. In this scenario we use FG-300C as Fortigate firewall and cisco 3750X as switches. In fortigates we will define to deferent VDOMs. EXRTRANET and INTRANET. Please note to the following diagram:  As you can see in this scenario we have a stack switch in our network. The concept of connectivity in our scenario is that interfaces in firewall 1 are connected to interfaces in Switch member 1 and so on interfaces on firewall 2 are connected to interfaces in switch member 2. In this scenario we will use VLAN plan as follow VLAN20 for EXTRANET-INSIDE zone. VLAN21 for EXTRANET-OUTSIDE zone. VLAN22 for INTRANET-INSIDE zone. VLAN23 for INTRANET-OUTSIDE zone. Letβs start to configuring switches: The first step is VLAN configuration.  Now we should assign VLANs to interfaces. ! interface GigabitEthernet1/0/5 description <<FG1- EXTRANET-INSIDE -INTERFACE>> switchport access vlan 20 switchport mode access end ! interface GigabitEthernet1/0/6 description <<FG1 EXTRANET-OUTSIDE -INTERFACE>> switchport access vlan 21 switchport mode access end ! interface GigabitEthernet1/0/2 description <<FG1- INTRANET-INSIDE -INTERFACE>> switchport access vlan 22 switchport mode access end ! interface GigabitEthernet1/0/6 description <<FG1 INTRANET-OUTSIDE -INTERFACE>> switchport access vlan 23 switchport mode access end ! And like this method we should configure interfaces for second firewall: ! interface GigabitEthernet2/0/5 description <<FG1- EXTRANET-INSIDE -INTERFACE>> switchport access vlan 20 switchport mode access end ! interface GigabitEthernet2/0/6 description <<FG1 EXTRANET-OUTSIDE -INTERFACE>> switchport access vlan 21 switchport mode access end ! interface GigabitEthernet2/0/2 description <<FG1- INTRANET-INSIDE -INTERFACE>> switchport access vlan 22 switchport mode access end ! interface GigabitEthernet2/0/6 description <<FG1 INTRANET-OUTSIDE -INTERFACE>> switchport access vlan 23 switchport mode access end ! Now it is time to configure HA in firewalls. As you can see in following image we use default heartbeat links. (Port3 and port4). For security reasons I masked some information.  Follow these configuration on both devices: FG-1 # config global FG-1 (global) # config system ha FG-1 (ha) # show config system ha set group-id 1 set group-name "FG-CLUSTER" set mode a-p set password ENC 4Lye/lPUw1UNn/O1unxY3hmO+ set vcluster2 enable set override enable set priority 100 config secondary-vcluster set override enable set priority 200 set vdom "INTRANET" end end And make mirror of this configuration on 2ND device: FG-2 # FG-2 # config global FG-2 (global) # config system ha FG-2 (ha) # show config system ha set group-id 1 set group-name "FG-CLUSTER" set mode a-p set password ENC WMDvKIyun1ryvO5EPnIiuPendu7zeruS7 set vcluster2 enable set override enable set priority 200 config secondary-vcluster set override enable set priority 100 set vdom "EXTRANET" end end As you can see I enable Virtual clustering in my HA. This feature help me to load balance traffics of various VDOMs in deferent cluster members.
author | hashem-s |
---|---|
permlink | fortigate-ha-and-virtual-cluster-configuration |
category | fortigate |
json_metadata | {"tags":["fortigate","ha","cluster","network","firewall"],"image":["https://steemitimages.com/DQmVCgSqHuxwEbBQZYr9UE6Fmtmi1L5h2jYRPMr1b1brPa9/0.jpg","https://steemitimages.com/DQmZsKVnD23iZiemHz3mLNyTYNPt6KbYpnBF9mJaBTCFmT1/1.JPG","https://steemitimages.com/DQmX8WGVLpcp8ubPfQGgwLVtoyLUZ8ehLyp3rnotLzNpnaL/2.jpg"],"app":"steemit/0.1","format":"markdown"} |
created | 2017-07-16 13:19:39 |
last_update | 2017-07-16 13:19:39 |
depth | 0 |
children | 3 |
last_payout | 2017-07-23 13:19:39 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.861 HBD |
curator_payout_value | 0.014 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 3,773 |
author_reputation | 12,388,266,150 |
root_title | "FORTIGATE HA AND VIRTUAL CLUSTER CONFIGURATION" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 0 |
post_id | 8,668,537 |
net_rshares | 176,695,498,009 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
germanaure | 0 | 7,456,430,313 | 100% | ||
abh12345 | 0 | 5,504,129,883 | 14% | ||
meysam | 0 | 148,412,091,660 | 100% | ||
deadim | 0 | 0 | 50.07% | ||
mahdiyari | 0 | 10,579,441,459 | 35% | ||
aliarami | 0 | 2,189,013,288 | 100% | ||
hashem-s | 0 | 1,160,703,527 | 100% | ||
mikolla | 0 | 0 | 100% | ||
cosmicboy123 | 0 | 703,092,266 | 100% | ||
koreaphoto | 0 | 0 | 10.25% | ||
kanokwan | 0 | 0 | 53.89% | ||
itman | 0 | 690,595,613 | 100% | ||
jesca | 0 | 0 | 100% | ||
riskasuandi | 0 | 0 | 100% | ||
afietchan | 0 | 0 | 100% | ||
katak | 0 | 0 | 100% | ||
rahmatidhami | 0 | 0 | 100% | ||
arm2000 | 0 | 0 | 100% | ||
albanna | 0 | 0 | 100% | ||
joelpaseearon | 0 | 0 | 100% | ||
emirzafirdaus | 0 | 0 | 100% | ||
steemfuad | 0 | 0 | 100% | ||
intania | 0 | 0 | 100% | ||
syahri | 0 | 0 | 100% | ||
imamalkimas | 0 | 0 | 100% | ||
arfie | 0 | 0 | 100% | ||
razi.teuku | 0 | 0 | 100% | ||
ddccdd | 0 | 0 | 100% | ||
rkdupron | 0 | 0 | 100% | ||
tarmizijutawan | 0 | 0 | 100% | ||
vampirexter | 0 | 0 | 25.9% | ||
mahyul | 0 | 0 | 100% | ||
metinyolcu | 0 | 0 | 100% | ||
kanchana | 0 | 0 | 100% | ||
dolles7 | 0 | 0 | 100% | ||
zulfanefedi | 0 | 0 | 100% | ||
regiel | 0 | 0 | 100% | ||
yorsy | 0 | 0 | 100% | ||
kramat23 | 0 | 0 | 100% | ||
kowinnhtunn | 0 | 0 | 100% | ||
samsulbahari | 0 | 0 | 100% | ||
mrwincaste | 0 | 0 | 100% | ||
fakhrurradhi | 0 | 0 | 100% | ||
larryt20 | 0 | 0 | 100% | ||
sufi0483 | 0 | 0 | 100% | ||
muhammadrifqi | 0 | 0 | 100% | ||
afril | 0 | 0 | 100% | ||
waizinthwe | 0 | 0 | 0% | ||
towardgold | 0 | 0 | 100% | ||
sadeghr1987 | 0 | 0 | 50.93% | ||
alinoroozi | 0 | 0 | 100% | ||
davidcuenc | 0 | 0 | 100% | ||
nurilsejati | 0 | 0 | 100% | ||
boyrasyid | 0 | 0 | 100% | ||
adithramdas | 0 | 0 | 100% | ||
moncadadavid15 | 0 | 0 | 100% |
great post...i made a special thanking post including you as special ..please check in my blog
author | learnandgrow |
---|---|
permlink | re-hashem-s-fortigate-ha-and-virtual-cluster-configuration-20171029t133448382z |
category | fortigate |
json_metadata | {"tags":["fortigate"],"app":"steemit/0.1"} |
created | 2017-10-29 13:34:51 |
last_update | 2017-10-29 13:34:51 |
depth | 1 |
children | 0 |
last_payout | 2017-11-05 13:34:51 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 94 |
author_reputation | 14,597,806,002,352 |
root_title | "FORTIGATE HA AND VIRTUAL CLUSTER CONFIGURATION" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 18,876,608 |
net_rshares | 0 |
Glad to see Iranians at Steemit :)
author | mahdiyari |
---|---|
permlink | re-hashem-s-fortigate-ha-and-virtual-cluster-configuration-20170716t183923937z |
category | fortigate |
json_metadata | {"tags":["fortigate"],"app":"steemit/0.1"} |
created | 2017-07-16 18:40:21 |
last_update | 2017-07-16 18:40:21 |
depth | 1 |
children | 1 |
last_payout | 2017-07-23 18:40:21 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 34 |
author_reputation | 199,864,818,197,856 |
root_title | "FORTIGATE HA AND VIRTUAL CLUSTER CONFIGURATION" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 8,693,953 |
net_rshares | 0 |
me too
author | hashem-s |
---|---|
permlink | re-mahdiyari-re-hashem-s-fortigate-ha-and-virtual-cluster-configuration-20170717t041210011z |
category | fortigate |
json_metadata | {"tags":["fortigate"],"app":"steemit/0.1"} |
created | 2017-07-17 04:12:09 |
last_update | 2017-07-17 04:12:09 |
depth | 2 |
children | 0 |
last_payout | 2017-07-24 04:12:09 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 HBD |
curator_payout_value | 0.000 HBD |
pending_payout_value | 0.000 HBD |
promoted | 0.000 HBD |
body_length | 6 |
author_reputation | 12,388,266,150 |
root_title | "FORTIGATE HA AND VIRTUAL CLUSTER CONFIGURATION" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 HBD |
percent_hbd | 10,000 |
post_id | 8,730,619 |
net_rshares | 0 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
hashem-s | 0 | 0 | 0% |