HA active-active cluster setup
An HA Active-Active (A-A) cluster can be set up using the GUI or CLI.
FGCP in Active-Active mode cannot load balance any sessions that traverse NPU VDOM links or regular VDOM links. If Active-Active session load balancing between VDOMs is required, use an external router to handle the inter-VDOM routing. |
This example uses the following network topology:
To set up an HA A-A cluster using the GUI:
- Make all the necessary connections as shown in the topology diagram.
- Log into one of the FortiGates.
- Go to System > HA and set the following options:
Mode
Active-Active
Device priority
128 or higher
Group name
Example_cluster
Heartbeat interfaces
ha1 and ha2
Except for the device priority, these settings must be the same on all FortiGates in the cluster.
The group ID can be configured in the CLI and must be the same in all HA members in order to form a cluster. The group ID can impact the definition of the virtual MAC addresses of interfaces. See Determining VMAC addresses for more details.
- Leave the remaining settings as their default values. They can be changed after the cluster is in operation.
- Click OK.
The FortiGate negotiates to establish an HA cluster. Connectivity with the FortiGate may be temporarily lost as the HA cluster negotiates and the FGCP changes the MAC addresses of the FortiGate's interfaces.
- Factory reset the other FortiGate that will be in the cluster, configure GUI access, then repeat steps 1 to 5, omitting setting the device priority, to join the cluster.
To set up an HA A-A cluster using the CLI:
- Make all the necessary connections as shown in the topology diagram.
- Log into one of the FortiGates.
- Change the hostname of the FortiGate:
config system global set hostname Example1_host end
Changing the host name makes it easier to identify individual cluster units in the cluster operations.
- Enable HA:
config system ha set mode a-a set group-name Example_cluster set hbdev ha1 10 ha2 20 end
- Leave the remaining settings as their default values. They can be changed after the cluster is in operation.
- Repeat steps 1 to 5 on the other FortiGate devices to join the cluster.