Fortinet white logo
Fortinet white logo

FortiOS Carrier

FGCP PFCP tunnel synchronization

FGCP PFCP tunnel synchronization

FortiGate Clustering Protocol (FGCP) HA provides failover protection for PFCP tunnels. This means that an active-passive cluster of two FortiGates licensed for FortiOS Carrier can provide FortiOS Carrier firewall services even when one of the FortiGates in the cluster encounters a problem that would result in complete loss of connectivity for a standalone FortiGate. This failover protection provides a backup mechanism that can be used to reduce the risk of unexpected downtime, especially for mission-critical environments.

Fortinet recommends FGCP PFCP tunnel synchronization for an active-passive FGCP cluster of two FortiGates.

FGCP HA can be configured to synchronize TCP and UDP sessions. However synchronizing a session is only part of the solution if the goal is to continue PFCP processing on a synchronized session after an HA failover. For that to be successful, FortiOS Carrier also synchronizes the PFCP tunnel state. So, once the primary FortiGate in the FGCP cluster completes tunnel setup, the PFCP tunnel is synchronized to the secondary or backup FortiGate in the cluster. PFCP tunnel synchronization includes synchronizing all PFCP tunnel information including session timers.

PFCP traffic will only flow without interruption after an HA failover if bidirectional PFCP policies have been configured: an internal (PFCP server) to external (all) UDP port PFCP policy, and an external (all) to internal (PFCP server) UDP port PFCP policy. If either policy is missing then traffic may be interrupted until traffic flows in the opposite direction.

For more information about FGCP HA, see High Availability.

FGCP PFCP tunnel synchronization

FGCP PFCP tunnel synchronization

FortiGate Clustering Protocol (FGCP) HA provides failover protection for PFCP tunnels. This means that an active-passive cluster of two FortiGates licensed for FortiOS Carrier can provide FortiOS Carrier firewall services even when one of the FortiGates in the cluster encounters a problem that would result in complete loss of connectivity for a standalone FortiGate. This failover protection provides a backup mechanism that can be used to reduce the risk of unexpected downtime, especially for mission-critical environments.

Fortinet recommends FGCP PFCP tunnel synchronization for an active-passive FGCP cluster of two FortiGates.

FGCP HA can be configured to synchronize TCP and UDP sessions. However synchronizing a session is only part of the solution if the goal is to continue PFCP processing on a synchronized session after an HA failover. For that to be successful, FortiOS Carrier also synchronizes the PFCP tunnel state. So, once the primary FortiGate in the FGCP cluster completes tunnel setup, the PFCP tunnel is synchronized to the secondary or backup FortiGate in the cluster. PFCP tunnel synchronization includes synchronizing all PFCP tunnel information including session timers.

PFCP traffic will only flow without interruption after an HA failover if bidirectional PFCP policies have been configured: an internal (PFCP server) to external (all) UDP port PFCP policy, and an external (all) to internal (PFCP server) UDP port PFCP policy. If either policy is missing then traffic may be interrupted until traffic flows in the opposite direction.

For more information about FGCP HA, see High Availability.