54
01-28008-0111-20050128
Fortinet Inc.
Connecting the cluster to your networks
High availability installation
Inserting an HA cluster into your network temporarily interrupts communications on
the network because new physical connections are being made to route traffic through
the cluster. Also, starting the cluster interrupts network traffic until the individual
FortiGate units in the cluster are functioning and the cluster completes negotiation.
Cluster negotiation normally takes just a few seconds. During system startup and
negotiation all network traffic is dropped.
To connect the cluster
1
Connect the cluster units:
• Connect the internal interfaces of each FortiGate unit to a switch or hub connected
to your internal network.
• Connect the WAN1 interfaces of each FortiGate unit to a switch or hub connected
to your external network.
• Connect the DMZ interfaces of the FortiGate units to another switch or hub. By
default the DMZ interfaces are used for HA heartbeat communications. These
interfaces should be connected together for the HA cluster to function.
• Optionally connect the WAN2 interface of each FortiGate unit to a switch or hub
connected a second external network.
Figure 12: HA network configuration
INTERNAL
DMZ
4
3
2
1
LINK 100
LINK 100
LINK 100
LINK 100
LINK 100
LINK 100
LINK 100
WAN1
WAN2
PWR
STATUS
INTERNAL
DMZ
4
3
2
1
LINK 100
LINK 100
LINK 100
LINK 100
LINK 100
LINK 100
LINK 100
WAN1
WAN2
PWR
STATUS
Internet
Internal Network
Internal
Internal
WAN1
WAN1
DMZ
DMZ
Hub or
Switch
Hub or
Switch
Router