Chapter 9 High Availability for FortiOS 5.0 : Full mesh HA : Example: full mesh HA configuration : Configuring FortiGate-620B units for HA operation - web‑based manager
  
Configuring FortiGate-620B units for HA operation - web‑based manager
Each FortiGate-620B unit in the cluster must have the same HA configuration.
To configure the FortiGate-620B units for HA operation
1. Connect to the web‑based manager of one of the FortiGate-620B units.
2. On the System Information dashboard widget, beside Host Name select Change.
3. Enter a new Host Name for this FortiGate unit.
New Name
620_ha_1
4. Go to System > Config > HA and change the following settings.
Mode
Active-Active
 
Group Name
Rexample1.com
 
Password
RHA_pass_1
 
Heartbeat Interface
 
Enable
Priority
port5
Select
50
port6
Select
50
5. Select OK.
The FortiGate unit negotiates to establish an HA cluster. When you select OK you may temporarily lose connectivity with the FortiGate unit as the HA cluster negotiates and the FGCP changes the MAC address of the FortiGate unit interfaces (see “Cluster virtual MAC addresses”). The MAC addresses of the FortiGate‑620B interfaces change to the following virtual MAC addresses:
port1 interface virtual MAC: 00-09-0f-09-00-00
port10 interface virtual MAC: 00-09-0f-09-00-01
port11 interface virtual MAC: 00-09-0f-09-00-02
port12 interface virtual MAC: 00-09-0f-09-00-03
port13 interface virtual MAC: 00-09-0f-09-00-04
port14 interface virtual MAC: 00-09-0f-09-00-05
port15 interface virtual MAC: 00-09-0f-09-00-06
port16 interface virtual MAC: 00-09-0f-09-00-07
port17 interface virtual MAC: 00-09-0f-09-00-08
port18 interface virtual MAC: 00-09-0f-09-00-09
port19 interface virtual MAC: 00-09-0f-09-00-0a
port2 interface virtual MAC: 00-09-0f-09-00-0b
port20 interface virtual MAC: 00-09-0f-09-00-0c
port3 interface virtual MAC: 00-09-0f-09-00-0d
port4 interface virtual MAC: 00-09-0f-09-00-0e
port5 interface virtual MAC: 00-09-0f-09-00-0f
port6 interface virtual MAC: 00-09-0f-09-00-10
port7 interface virtual MAC: 00-09-0f-09-00-11
port8 interface virtual MAC: 00-09-0f-09-00-12
port9 interface virtual MAC: 00-09-0f-09-00-13
To be able to reconnect sooner, you can update the ARP table of your management PC by deleting the ARP table entry for the FortiGate unit (or just deleting all arp table entries). You may be able to delete the arp table of your management PC from a command prompt using a command similar to arp -d.
You can use the get hardware nic (or diagnose hardware deviceinfo nic) CLI command to view the virtual MAC address of any FortiGate unit interface. For example, use the following command to view the port1 interface virtual MAC address (Current_HWaddr) and the port1 permanent MAC address (Permanent_HWaddr):
get hardware nic port1
.
.
.
MAC: 00:09:0f:09:00:00
Permanent_HWaddr: 02:09:0f:78:18:c9
.
.
.
6. Power off the first FortiGate unit.
7. Repeat these steps for the second FortiGate unit.
Set the second FortiGate unit host name to:
New Name
620_ha_2
To connect the cluster to your network
1. Make the following physical network connections for 620_ha_1:
Port1 to Sw1 (active)
Port2 to Sw2 (inactive)
Port3 to Sw3 (active)
Port4 to Sw4 (inactive)
2. Make the following physical network connections for 620_ha_2:
Port1 to Sw2 (active)
Port2 to Sw1 (inactive)
Port3 to Sw4 (active)
Port4 to Sw3 (inactive)
3. Connect Sw3 and Sw4 to the internal network.
4. Connect Sw1 and Sw2 to the external router.
5. Enable ISL communication between Sw1 and Sw2 and between Sw3 and Sw4.
6. Power on the cluster units.
The units start and negotiate to choose the primary unit and the subordinate unit. This negotiation occurs with no user intervention.
When negotiation is complete the cluster is ready to be configured for your network.
To view cluster status
Use the following steps to view the cluster dashboard and cluster members list to confirm that the cluster units are operating as a cluster.
1. View the system dashboard.
The System Information dashboard widget shows the Cluster Name (Rexample1.com) and the host names and serial numbers of the Cluster Members. The Unit Operation widget shows multiple cluster units.
2. Go to System > Config > HA to view the cluster members list.
The list shows two cluster units, their host names, their roles in the cluster, and their priorities. You can use this list to confirm that the cluster is operating normally.
To troubleshoot the cluster configuration
If the cluster members list and the dashboard does not display information for both cluster units the FortiGate units are not functioning as a cluster. See “Troubleshooting HA clusters” to troubleshoot the cluster.
To add basic configuration settings and the redundant interfaces
Use the following steps to add a few basic configuration settings.
1. Log into the cluster web‑based manager.
2. Go to System > Admin > Administrators.
3. For admin, select the Change Password icon
4. Enter and confirm a new password.
5. Select OK.
6. Go to Router > Static > Static Routes and temporarily delete the default route.
You cannot add an interface to a redundant interface if any settings (such as the default route) are configured for it.
7. Go to System > Network > Interfaces and select Create New and configure the redundant interface to connect to the Internet.
Name
Port1_Port2
Type
Redundant
Physical Interface Members
Selected Interfaces
port1, port2
IP/Netmask
172.20.120.141/24
8. Select OK.
9. Select Create New and configure the redundant interface to connect to the internal network.
Name
Port3_Port4
Type
Redundant
Physical Interface Members
Selected Interfaces
port3, port4
IP/Netmask
10.11.101.100/24
Administrative Access
HTTPS, PING, SSH
10. Select OK.
The virtual MAC addresses of the FortiGate‑620B interfaces change to the following. Notice that port1 and port2 both have the port1 virtual MAC address and port3 and port4 both have the port3 virtual MAC address:
port1 interface virtual MAC: 00-09-0f-09-00-00
port10 interface virtual MAC: 00-09-0f-09-00-01
port11 interface virtual MAC: 00-09-0f-09-00-02
port12 interface virtual MAC: 00-09-0f-09-00-03
port13 interface virtual MAC: 00-09-0f-09-00-04
port14 interface virtual MAC: 00-09-0f-09-00-05
port15 interface virtual MAC: 00-09-0f-09-00-06
port16 interface virtual MAC: 00-09-0f-09-00-07
port17 interface virtual MAC: 00-09-0f-09-00-08
port18 interface virtual MAC: 00-09-0f-09-00-09
port19 interface virtual MAC: 00-09-0f-09-00-0a
port2 interface virtual MAC: 00-09-0f-09-00-00 (same as port1)
port20 interface virtual MAC: 00-09-0f-09-00-0c
port3 interface virtual MAC: 00-09-0f-09-00-0d
port4 interface virtual MAC: 00-09-0f-09-00-0d (same as port3)
port5 interface virtual MAC: 00-09-0f-09-00-0f
port6 interface virtual MAC: 00-09-0f-09-00-10
port7 interface virtual MAC: 00-09-0f-09-00-11
port8 interface virtual MAC: 00-09-0f-09-00-12
port9 interface virtual MAC: 00-09-0f-09-00-13
11. Go to Router > Static > Static Routes.
12. Add the default route.
Destination IP/Mask
0.0.0.0/0.0.0.0
Gateway
172.20.120.2
Device
Port1_Port2
Distance
10
13. Select OK.
To configure HA port monitoring for the redundant interfaces
1. Go to System > Config > HA.
2. In the cluster members list, edit the primary unit.
3. Configure the following port monitoring for the redundant interfaces:
 
Port Monitor
Port1_Port2
Select
Port3_Port4
Select
4. Select OK.