Fortinet white logo
Fortinet white logo

FortiGate-7000F Administration Guide

FortiGate 7000F FGSP

FortiGate 7000F FGSP

FortiGate 7000F supports the FortiGate Session Life Support Protocol (FGSP) (also called standalone session sync) to synchronize sessions among up to four FortiGate 7000Fs

For details about FGSP, see: FGSP.

FortiGate 7000F FGSP support has the following limitations:

  • Only the M1 to M4 interfaces of both FIMs can be used for FGSP session synchronization. Session synchronization can occur over individual M1 to M4 interfaces or over a LAG consisting of two or more of the M1 to M4 interfaces.

  • Session synchronization takes place between the peer IP addresses over L3. SLBC platforms do not support L2 session synchronization links. The session-sync-dev option is not supported.

  • FortiGate 7000F FGSP doesn't support setting up IPv6 session filters using the config session-sync-filter option.
  • Asymmetric IPv6 SCTP traffic sessions are not supported. These sessions are dropped.
  • Inter-cluster session synchronization, or FGSP between FGCP clusters, is not supported for the FortiGate 7000F.
  • FGSP IPsec tunnel synchronization is not supported.
  • Fragmented packet synchronization is not supported.

You can use configuration synchronization to synchronize the configurations of the FortiGate 7000Fs in the FGSP deployment (see Standalone configuration synchronization). You can use the M1 to M4 interfaces for configuration synchronization. You can also configure the FortiGate 7000Fs separately or use FortiManager to keep key parts of the configuration, such as security policies, synchronized.

FortiGate 7000F FGSP

FortiGate 7000F FGSP

FortiGate 7000F supports the FortiGate Session Life Support Protocol (FGSP) (also called standalone session sync) to synchronize sessions among up to four FortiGate 7000Fs

For details about FGSP, see: FGSP.

FortiGate 7000F FGSP support has the following limitations:

  • Only the M1 to M4 interfaces of both FIMs can be used for FGSP session synchronization. Session synchronization can occur over individual M1 to M4 interfaces or over a LAG consisting of two or more of the M1 to M4 interfaces.

  • Session synchronization takes place between the peer IP addresses over L3. SLBC platforms do not support L2 session synchronization links. The session-sync-dev option is not supported.

  • FortiGate 7000F FGSP doesn't support setting up IPv6 session filters using the config session-sync-filter option.
  • Asymmetric IPv6 SCTP traffic sessions are not supported. These sessions are dropped.
  • Inter-cluster session synchronization, or FGSP between FGCP clusters, is not supported for the FortiGate 7000F.
  • FGSP IPsec tunnel synchronization is not supported.
  • Fragmented packet synchronization is not supported.

You can use configuration synchronization to synchronize the configurations of the FortiGate 7000Fs in the FGSP deployment (see Standalone configuration synchronization). You can use the M1 to M4 interfaces for configuration synchronization. You can also configure the FortiGate 7000Fs separately or use FortiManager to keep key parts of the configuration, such as security policies, synchronized.