Configuring the FortiGate for the Network
High availability installation
FortiGate-5000 series Installation Guide
01-28011-0259-20060210
39
Installing and configuring the cluster
When negotiation is complete the you can configure the cluster as if it was a single
FortiGate-5000 module.
•
If you are installing a NAT/Route mode cluster, use the information in
“NAT/Route
mode installation” on page 17
to install the cluster on your network
•
If you are installing a Transparent mode cluster, use the information in
“NAT/Route
mode installation” on page 17
to install the cluster on your network.
The configurations of all of the FortiGate-5000 in the cluster are synchronized so that
the FortiGate-5000 modules can function as a cluster. Because of this
synchronization, you configure and manage the HA cluster instead of managing the
individual FortiGate-5000 modules in the cluster. You can configure and manage the
cluster by connecting to the cluster web-based manager using any cluster interface
configured for HTTPS administrative access. You can also configure and manage the
cluster by connecting to the CLI using any cluster interface configured for SSH
administrative access.
When you connect to the cluster, you are actually connecting to the primary cluster
module. The cluster automatically synchronizes all configuration changes to the
subordinate modules in the cluster as you make the changes.
The only configuration settings that are not synchronized are the HA configuration
(except for the interface heartbeat device and monitoring configuration) and the
FortiGate host name.
For more information about configuring a cluster, see the
FortiGate Administration
Guide
.
Clustering FortiGate-5000 series chassis
The FortiSwitch-5003 module provides full HA clustering capabilities to provide inter-
chassis communication. The FortiSwitch-5003 acts as the switch, providing automatic
connection through port 9 and 10 the backplane of the chassis.
You can use any of the available 10/100/1000 ports on the FortiSwitch-5003 module
to create an inter-chassis HA cluster.
Using two FortiSwitch-5003 modules in both chassis provides redundant inter-chassis
communication with no single point of failure.
The diagrams shown also apply to the FortiGate-5140 chassis.
Figure 11: FortiGate inter-chassis cluster using a single FortiSwitch-5003 module
PWR ACC
STA IPM
CONSOLE
USB
1
2
3
4
5
6
7
8
PWR ACC
STA IPM
CONSOLE
USB
1
2
3
4
5
6
7
8
PWR ACC
STA IPM
CONSOLE
USB
1
2
3
4
5
6
7
8
1
2
2
3
4
5
ShMC
1
ShMC
POWER
ON
MANAGEMENT
SYSTEM
E1
ZRE
LED MODE
15
14
13
12
11
10
9
8
7
6
5
4
3
2
1
0
E2
OK
CLK
INT
EXT
FL
T
HOT SW
AP
RESET
FL
T
CONSOLE
E T H O
R S 2 3 2
Z R E 0
Z R E 1
Z R E 2
HOT SWAP
STATUS
ALARMS
MINOR
ALARM
RESET
CRITICAL
MAJOR
PWR ACC
STA IPM
CONSOLE
USB
1
2
3
4
5
6
7
8
PWR ACC
STA IPM
CONSOLE
USB
1
2
3
4
5
6
7
8
PWR ACC
STA IPM
CONSOLE
USB
1
2
3
4
5
6
7
8
1
2
2
3
4
5
ShMC
1
ShMC
POWER
ON
MANAGEMENT
SYSTEM
E1
ZRE
LED MODE
15
14
13
12
11
10
9
8
7
6
5
4
3
2
1
0
E2
OK
CLK
INT
EXT
FL
T
HOT SW
AP
RESET
FL
T
CONSOLE
E T H O
R S 2 3 2
Z R E 0
Z R E 1
Z R E 2
HOT SWAP
STATUS
ALARMS
MINOR
ALARM
RESET
CRITICAL
MAJOR
PWR ACC
STA IPM
CONSOLE
USB
1
2
3
4
5
6
7
8
PWR ACC
STA IPM
CONSOLE
USB
1
2
3
4
5
6
7
8