Configuring FortiAnalyzer HA
To configure FortiAnalyzer HA:
- On FortiAnalyzer, configure high availability at System Settings > HA.
See the FortiAnalyzer Administration Guide for more information on configuring HA.
When configuring HA, use the primary private IP as the Peer IP and the external static IP as the Cluster Virtual IP.
- Import the Azure Root CA to FortiAnalyzer.
In order for the fazutil to call the Azure API successfully, you must import the Azure Cloud CA certificate to each FortiAnalyzer instance.
For more information on the CA used by Microsoft Entra ID (formerly Azure AD), see https://learn.microsoft.com/en-us/azure/security/fundamentals/azure-CA-details.- Go to System Settings > Certificates.
- Click Create New/Import.
- Browse to the file location and select the certificate, or drag-and-drop it in the Certificate File field.
- Enter the Certificate Name.
- Click OK.