FortiManager-HA support automatic VRRP failover in Azure 7.4.2
FortiManager-HA support automatic VRRP failover in Azure.
To configure automatic VRRP failover in Azure:
-
Create FortiManager-VM in one ResourceGroup in same or different subnets.
-
Allocate a secondary private IP (static) to be used as VIP of FortiManager-HA. Secondary IP will be assigned to the instance when its mode transitioned to master by fmgutil to call Azure cloud APIs within the instance itself
-
Or create a static public IP in the ResourceGroup to be used as VIP.
-
Enable Managed Identity for the VM and assign role with read-write access to the resource group. This is for VM to re-assign VIP.
-
Configure FortiManager-HA, use private IP as peer IP, and the static public IP as VIP.
To configure FortiManager HA:
-
On FortiManager, configure high availability at System Settings > HA.
See the FortiManager Administration Guide for more information on configuring HA.
When configuring HA, use the primary private IP as the Peer IP and the external static IP as the Cluster Virtual IP.
-
Import the Azure Root CA to FortiManager. In order for the fmgutil to call the Azure API successfully, you must import the Azure Cloud CA certificate to each FortiManager instance. For more information on the CA used by Microsoft Entra ID (formerly Azure AD), see https://learn.microsoft.com/en-us/azure/security/fundamentals/azure-CA-details.
-
Go to System Settings > Certificates > CA Certificates.
-
Click Import.
-
Browse to the file location and select it, or drag-and-drop it into the pop-up window.
-
Click OK.
-