Fortinet black logo

Handbook

Hyper-V HA

6.0.0
Copy Link
Copy Doc ID 4afb0436-a998-11e9-81a4-00505692583a:450791
Download PDF

Hyper-V HA

Support for MAC address spoofing is required for FortiGate-VM for Hyper-V to support FortiGate Clustering Protocol (FGCP) high availability (HA).

As the FGCP applies virtual MAC addresses to FortiGate data interfaces, and because these virtual MAC addresses mean that matching interfaces of different FortiGate-VM instances will have the same virtual MAC addresses, you have to configure Hyper-V to allow MAC spoofing. You should only enable MAC spoofing for FortiGate-VM data interfaces; you should not enable MAC spoofing for FortiGate HA heartbeat interfaces.

With the correct MAC spoofing settings you should be able to configure HA between two or more FortiGate-VM for Hyper-V instances.

Hyper-V HA

Support for MAC address spoofing is required for FortiGate-VM for Hyper-V to support FortiGate Clustering Protocol (FGCP) high availability (HA).

As the FGCP applies virtual MAC addresses to FortiGate data interfaces, and because these virtual MAC addresses mean that matching interfaces of different FortiGate-VM instances will have the same virtual MAC addresses, you have to configure Hyper-V to allow MAC spoofing. You should only enable MAC spoofing for FortiGate-VM data interfaces; you should not enable MAC spoofing for FortiGate HA heartbeat interfaces.

With the correct MAC spoofing settings you should be able to configure HA between two or more FortiGate-VM for Hyper-V instances.