Professional Documents
Culture Documents
Fortigate Infrastructure: High Availability (Ha)
Fortigate Infrastructure: High Availability (Ha)
Fortigate Infrastructure: High Availability (Ha)
FortiOS 7.0
© Copyright Fortinet Inc. All rights reserved. LastLast
Modified:
Modified:
Friday,
Friday,
JulyJuly
29, 29,
20222022
Lesson Overview
HA Operation Modes
HA Cluster Synchronization
Objectives
• Identify the different operation modes for HA
• Understand the primary FortiGate election in an HA cluster
3
What Is FortiGate HA?
Switch
FortiGate Devices
Switch
Secondaries
If primary fails, a
secondary takes over
• If the primary FortiGate is rebooted or shut down, it becomes the secondary FortiGate
and waits for the traffic to failover to the new primary, before it reboots or shuts down
Port 1 Port 2
Heartbeat 1 Heartbeat 2
Port 1 Port 2
Greater Less
HAPriority
Uptime
2. What is the default criteria (override disabled) for selecting the HA primary device in an
HA cluster?
A. Connected monitored ports > HA uptime > priority > serial number
B. Priority > HA uptime > connected monitored ports > serial number
HA Operation Modes
HA Cluster Synchronization
Objectives
• Identify the primary and secondary device tasks in an HA
cluster
• Identify what is synchronized between HA cluster members
• Configure session synchronization for seamless failover
13
Primary FortiGate Tasks
• Exchanges heartbeat hello packets with all the secondary devices
• Synchronizes its routing table, DHCP information, and part of its configuration to all the
secondary devices
• Can synchronize the information of some of the traffic sessions for seamless failover
• In active-active mode only:
• Distributes specific traffic among all the devices in the cluster
• Monitored ports are usually networks (interfaces) processing high priority traffic
• Avoid configuring interface monitoring for all interfaces
• Do not monitor dedicated heartbeat interfaces
• Can monitor VLAN interfaces
• Wait until a cluster is up and running and all interfaces are connected before enabling interface
monitoring
1. New secondary is
2. Primary compares its checksum of configuration added to cluster
with the new secondary checksum. If it is
different, it sends its configuration
New secondary
Configuration
Primary
1. Primary configuration is
changed
Secondary
Configuration
Primary
Configuration
• The primary FortiGate synchronizes all other configuration settings and other
configuration details related to HA settings
HA Operation Modes
HA Cluster Synchronization
Objectives
• Identify the HA failover types
• Interpret how an HA cluster in active-active mode distributes
traffic
• Implement virtual clustering per virtual domain (VDOM) in an
HA cluster
25
Failover Protection Types
• Device failover
• If the primary stops sending heartbeat packets, another FortiGate automatically takes its place
• Link failover
• The cluster can monitor some interfaces to determine if they are operating and connected
• If a monitored interface on the primary fails, the cluster elects a new primary
• Session failover
• When session pickup is enabled, the newly elected primary resumes active session, avoiding the need
to restart active session
• Memory utilization failover
• When configured, an HA failover can be triggered when memory utilization exceeds the threshold for a
specific amount of time
• Event logs, SNMP traps, and alert email record failover events
HA heartbeat interfaces
Primary
Former primary
Virtual MAC addresses
• Active-active HA cluster
• The primary updates the list of available secondary FortiGate devices and redistributes sessions to
prevent failed secondary devices
• Active-active HA cluster
• The primary receives all traffic and redirects some traffic to secondary devices
primary-physical MAC-port1
1 - SYN
2 - SYN
secondary-physical MAC-port1
Client secondary
3a - SYN
3b – SYN/ACK
port1
secondary-physical MAC-port1
port2 Server
secondary-physical MAC-port2
5 - ACK
secondary-physical MAC-port1
Client secondary
port1
port2 Server
secondary-physical MAC-port2
7 - SYN/ACK
secondary
port1
port2 8 - ACK Server
secondary-physical MAC-port2
4 - SYN/ACK
1 - SYN
primary-physical MAC port1/port2
2 - SYN 5 – SYN/ACK
8 - ACK
7 - ACK secondary-physical MAC port1/port2
Client
3 - SYN
Server
6 – SYN/ACK
port1 port2 9 - ACK
secondary-physical MAC-port1 secondary-physical MAC-port2
secondary
Active-Passive HA
FortiGate
HB 2
HB 1
FortiGate
2. You can configure virtual clustering between only ____ FortiGate devices with multiple
VDOMs in an active-passive HA cluster.
A. Two
B. Four
HA Operation Modes
HA Cluster Synchronization
Objectives
• Verify the normal operation of an HA cluster
• Configure an HA management interface
• Upgrade an HA cluster firmware
38
Checking the Status of the HA Using the GUI
• Add the HA status widget
[Kernel HA information]
vcluster 1, state=work, primary_ip=169.254.0.1, primary_id=0:
FGVM010000112065: Primary, ha_prio/o_ha_prio=0/0
FGVM010000065036: Secondary, ha_prio/o_ha_prio=1/1 Heartbeat interface IP 169.254.0.1
assigned to the highest serial number
is_manage_primary()=0, is_root_primary()=0
debugzone
global: 7b 05 62 17 8f cd 76 29 57 da 32 8e
root: 97 91 80 67 9d 97 e3 a1 dd 0d ca
all: e1 ad dd fb ff f6 e5 55 2c ed 3b
checksum
global: 7b 05 62 17 8f cd 76 29 57 da 32 8e
root: 97 91 80 67 9d 97 e3 a1 dd 0d ca
all: e1 ad dd fb ff f6 e5 55 2c ed 3b
1.The cluster upgrades the firmware on all the Firmware upgrade in progress....
secondaries Done.
3
2.A new primary is elected 2 Current Secondary(s)
3.The cluster upgrades the firmware in Remote # Get image from ha primary OK.
Check image OK.
the ..former primary Please wait for system to restart.
HA Operation Modes
HA Cluster Synchronization