System Config
HA
FortiGate-1000A/FA2 Administration Guide
01-28011-0254-20051115
101
Configuring an HA cluster
Use the following procedures to create an HA cluster consisting of two or more
FortiGate units. These procedures describe how to configure each of the FortiGate
units for HA operation and then how to connect the FortiGate units to form a cluster.
Once the cluster is connected you can configure it in the same way as you would
configure a standalone FortiGate unit.
•
To configure a FortiGate unit for HA operation
•
To connect a FortiGate HA cluster
•
To add a new unit to a functioning cluster
•
To configure weighted-round-robin weights
•
To configure load balancing TCP and virus scanning traffic
To configure a FortiGate unit for HA operation
Each FortiGate unit in the cluster must have the same HA configuration. Use the
following procedure to configure each FortiGate unit for HA operation.
1
Power on the FortiGate unit to be configured.
2
Connect to the web-based manager.
3
Give the FortiGate unit a unique host name.
See
“To change FortiGate host name” on page 38
. Use host names to identify
individual cluster units.
4
Go to
System > Config > HA
.
5
Select HA.
6
Select the HA mode.
7
Select a Group ID for the cluster.
The Group ID must be the same for all FortiGate units in the HA cluster.
8
Optionally change the Unit Priority.
See
“Unit Priority” on page 97
.
9
If required, select Override master.
See
“Override Master” on page 97
.
10
Enter and confirm a password for the HA cluster.
11
If you are configuring Active-Active HA, select a schedule.
See
“Schedule” on page 98
.
12
Select Apply.
The FortiGate unit negotiates to establish an HA cluster. When you select apply you
may temporarily lose connectivity with the FortiGate unit as the HA cluster negotiates
and because the FGCP changes the MAC address of the FortiGate unit interfaces
(see
“Group ID” on page 96
). To be able to reconnect sooner, you can update the ARP
table of your management PC by deleting the ARP table entry for the FortiGate unit.
Note:
The following procedure does not include steps for configuring heartbeat devices and
interface monitoring. Both of these HA settings should be configured after the cluster is up and
running.
Summary of Contents for FortiGate 1000A
Page 80: ...80 01 28011 0254 20051115 Fortinet Inc FortiGate IPv6 support System Network ...
Page 88: ...88 01 28011 0254 20051115 Fortinet Inc Dynamic IP System DHCP ...
Page 122: ...122 01 28011 0254 20051115 Fortinet Inc FortiManager System Config ...
Page 248: ...248 01 28011 0254 20051115 Fortinet Inc Protection profile Firewall ...
Page 260: ...260 01 28011 0254 20051115 Fortinet Inc CLI configuration User ...
Page 380: ...380 01 28011 0254 20051115 Fortinet Inc CLI configuration Log Report ...
Page 392: ...392 01 28011 0254 20051115 Fortinet Inc Glossary ...