High availability (HA) between availability zones (AZs) on Azure is supported.
Azure HA solves the problem of availability when a FortiGate goes down. Azure HA across AZs solves the problem of what happens when Azure goes down, which ensures the maximum amount of uptime for customers.
- Ensure FortiGate A and FortiGate B are in different availability zones in Azure.
In the following example, FortiGate A is in availability zone 1:
FortiGate B is in availability zone 2:
- For each FortiGate, go to Identity > System assigned, and set Status to On.
- For each FortiGate, under Add role assignment, set Role to Contributor.
- Set the public IP address:
- For the SKU option, select Standard.
- In the Availability zone list, select Zone-redundant.
When a failover is triggered, the secondary device becomes the primary device. Use the following diagnose command to confirm HA change:
# diagnose debug application awsd -1 # diagnose debug enable