Configure WiFi Controller for High Availability
Configuring the FortiGate WiFi controller in HA A-P mode allows redundancy and failover in case one member of the cluster fails. HA configurations can be very complex and contain many granular settings to fine-tune the behavior of your HA cluster. For more information, refer to the HA chapter of the FortiOS Admin Guide.
To configure the basic HA settings
- Go to System > HA.
- In Mode, select Active-Passive.
- In Device priority, enter
128
, the default.- When configuring the secondary WiFi controller, use
64
for the priority.
- When configuring the secondary WiFi controller, use
- Enter a Group name.
- The Group name should match on the secondary controller.
- Choose the Heartbeat Interfaces, these fields are often preconfigured.
-
For Heartbeat Interface Priority, this example uses 50, 50 for equal priority.
-
When you are finished, click OK.
Repeat the above setup for the Secondary WiFi Controller
- See Power on and the first login.
- Move the setup laptop Ethernet cable to the secondary FortiGate.
- The admin password should match the Primary.
- Use a different hostname for the secondary controller, such as "SecondaryWLANcontoller".
- See To configure the basic HA settings.
- Set the device priority of the secondary controller to 64.
- The group name should be identical on both units.
Synchronize the HA Controller Pair
- Connect the HA1 and HA2 ports of the controller pair using Ethernet cables.
- Add a (possibly temporary) MGMT switch, and connect each management port and the administrative laptop to the switch (or same untagged VLAN, or other equivalent).
- Open a browser to
https://192.168.1.99
and log in to the controller(s). The primary will respond. -
Go to System > HA and verify that both controllers are synchronized. If not, give it a few minutes.
Now any changes on the primary will be mirrored on the secondary.
- In this scenario, the Secondary Controller acts as a backup and only becomes active in the case of a Primary Controller failure where heartbeats cannot be detected over both HA ports within the configured threshold.