Fortinet white logo
Fortinet white logo

Azure vWAN SD-WAN NGFW Deployment Guide

7.2.0

Configuring FGSP on FortiGate NVAs (GUI)

Configuring FGSP on FortiGate NVAs (GUI)

In certain configurations, such as, redundant IPsec tunnels, traffic flow may return asymmetrically. When traffic returns asymmetrically, an initial connection could come in on one FortiGate, but the return packets might be sent to the other FortiGate. Supporting asymmetrical traffic requires FortiGate Session Life Support Protocol (also known as FGSP), which is a layer 3 session synchronization feature, to be enabled. Further, we must allow for rerouting of packets from one FortiGate to another in cases where IPS or other deep packet inspection is required.

Note

As an alternative to enabling FGSP, Source NAT (SNAT) can be used instead. For more information about Source NAT, see the FortiManager Administration Guide > SNAT Policy.

For more information about FGSP and the available options, see the FortiOS Administration Guide > FGSP.

To configure FGSP:
  1. On FortiManager, go to Device Manager > Device & Groups, and select the device group for the FortiGate NVAs. The FortiGate NVAs in the group are displayed in the content pane.
  2. In the content pane, select all devices in the group.
  3. Right-click the selected devices, and select FGSP Configuration from the More menu.

  4. Specify the configuration, and click OK

    The FGSP Column displays Configured for both devices.

  5. Note the information in the Device Name and IP Address columns of both FortiGate NVAs.

Configuring FGSP on FortiGate NVAs (GUI)

Configuring FGSP on FortiGate NVAs (GUI)

In certain configurations, such as, redundant IPsec tunnels, traffic flow may return asymmetrically. When traffic returns asymmetrically, an initial connection could come in on one FortiGate, but the return packets might be sent to the other FortiGate. Supporting asymmetrical traffic requires FortiGate Session Life Support Protocol (also known as FGSP), which is a layer 3 session synchronization feature, to be enabled. Further, we must allow for rerouting of packets from one FortiGate to another in cases where IPS or other deep packet inspection is required.

Note

As an alternative to enabling FGSP, Source NAT (SNAT) can be used instead. For more information about Source NAT, see the FortiManager Administration Guide > SNAT Policy.

For more information about FGSP and the available options, see the FortiOS Administration Guide > FGSP.

To configure FGSP:
  1. On FortiManager, go to Device Manager > Device & Groups, and select the device group for the FortiGate NVAs. The FortiGate NVAs in the group are displayed in the content pane.
  2. In the content pane, select all devices in the group.
  3. Right-click the selected devices, and select FGSP Configuration from the More menu.

  4. Specify the configuration, and click OK

    The FGSP Column displays Configured for both devices.

  5. Note the information in the Device Name and IP Address columns of both FortiGate NVAs.