Support Universal Connector for FortiManager HA 7.4.2
Universal Connector MEA redundancy supported by FortiManager HA.
To configure Universal Connector MEA redundancy in HA:
- Configure High Availability (HA) on the Primary and Secondary FortiManager
- On the Primary FortiManager, configure FortiManager HA in System Settings > HA.
- On the Secondary FortiManager, configure FortiManager HA in System Settings > HA.
- Verify that the cluster Status is Up.
- On the Primary FortiManager, configure FortiManager HA in System Settings > HA.
- Configure the Universal Connector Management Extension Application (MEA).
- Enable the Universal Connector MEA in the CLI of the Primary FortiManager by entering the following commands in the CLI:
config system docker
set status enable
set universalconnector enable
end
Go to Policy & Objects > Security Fabric > Endpoint/Identity > Create New and create a new connector. Set the Status toggle to On, and click OK.
Go to Management Extensions > Universal Connector, and click Create Connector to create a new connector.
Configure the connector's details, enable the connector, and add a filter group.
- Enable the Universal Connector MEA in the CLI of the Primary FortiManager by entering the following commands in the CLI:
-
Go to Policy & Objects > Firewall Objects > Addresses and create a new dynamic firewall address using the filter group from the Universal Connector.
-
Go to the Secondary FortiManager. The Universal Connector configuration has been backed up.
Dynamic firewall addresses have also been backed up. In the event that the Primary FortiManager fails, the Secondary FortiManager unit becomes the new Primary and assumes responsibility over resolving the IP addresses of dynamic firewall objects and pushing policies to FortiGates.