Fortinet black logo

Session-Aware Load Balancing Cluster Guide

Basic cluster NAT/Route mode configuration

5.2.10
Copy Link
Copy Doc ID 31a89d05-200d-11e9-b6f6-f8bc1258b856:354222
Download PDF

Basic cluster NAT/Route mode configuration

When all of the devices have been added to the cluster, configuring the cluster is just like configuring a standalone FortiGate unit operating with multiple VDOMs. When you first log into the primary worker you are logging into a FortiGate unit in multiple VDOM mode.

You can either log into the FortiController GUI and from there go to Load Balance > Status and connect to the worker GUI or you can connect directly to the worker primary unit using the External Management IP/Netmask.

No additional changes to the FortiController configuration are required. However, you can tune the FortiController configuration, see Changing load balancing settings

In the load balanced cluster the workers are configured with two VDOMs:

  • elbc-mgmt includes the mgmt interface and is used for management traffic. When you connect to the mgmt interface you connect to this VDOM. Normally you do not have to change the configuration of this VDOM.
  • root includes the fctrl/f1 to fctrl/f8 interfaces. Configure this VDOM to allow traffic through the cluster and to apply UTM and other FortiOS features to the traffic.

By default the root VDOM operates in NAT/Route mode. You can add more VDOMs that operate in NAT/Route or Transparent mode. If you add more VDOMs you must add some of the fctrl/f1 to fctrl/f8 interfaces to each VDOM. You can also add VLAN interfaces and add these interfaces to VDOMs.

Note FortiController interfaces other than the fctrl/f1 to fctrl/f8 interfaces are visible from the GUI and CLI. In a session-aware load balanced cluster these interfaces are not used for network traffic.

Basic cluster NAT/Route mode configuration

When all of the devices have been added to the cluster, configuring the cluster is just like configuring a standalone FortiGate unit operating with multiple VDOMs. When you first log into the primary worker you are logging into a FortiGate unit in multiple VDOM mode.

You can either log into the FortiController GUI and from there go to Load Balance > Status and connect to the worker GUI or you can connect directly to the worker primary unit using the External Management IP/Netmask.

No additional changes to the FortiController configuration are required. However, you can tune the FortiController configuration, see Changing load balancing settings

In the load balanced cluster the workers are configured with two VDOMs:

  • elbc-mgmt includes the mgmt interface and is used for management traffic. When you connect to the mgmt interface you connect to this VDOM. Normally you do not have to change the configuration of this VDOM.
  • root includes the fctrl/f1 to fctrl/f8 interfaces. Configure this VDOM to allow traffic through the cluster and to apply UTM and other FortiOS features to the traffic.

By default the root VDOM operates in NAT/Route mode. You can add more VDOMs that operate in NAT/Route or Transparent mode. If you add more VDOMs you must add some of the fctrl/f1 to fctrl/f8 interfaces to each VDOM. You can also add VLAN interfaces and add these interfaces to VDOMs.

Note FortiController interfaces other than the fctrl/f1 to fctrl/f8 interfaces are visible from the GUI and CLI. In a session-aware load balanced cluster these interfaces are not used for network traffic.