Fortinet fortigate-100a Betriebsanweisung

Seite von 388
90
01-28006-0068-20041105
Fortinet Inc.
HA configuration
System config
For most FortiGate models if you do not change the heartbeat device configuration, 
you would isolate the HA interfaces of all of the cluster units by connecting them all to 
the same switch. If the cluster consists of two FortiGate units you can connect the 
heartbeat device interfaces directly using a crossover cable.
HA heartbeat and data traffic are supported on the same FortiGate interface. In 
NAT/Route mode, if you decide to use the heartbeat device interfaces for processing 
network traffic or for a management connection, you can assign the interface any IP 
address. This IP address does not affect the heartbeat traffic. In Transparent mode, 
you can connect the interface to your network.
Monitor priorities
Monitor priorities and link failover is not supported for the internal interface.
Enable or disable monitoring a FortiGate interface to verify that the interface is 
functioning properly and connected to its network. If a monitored interface fails or is 
disconnected from its network the interface leaves the cluster. The cluster reroutes 
the traffic being processed by that interface to the same interface of another cluster 
unit in the cluster that still has a connection to the network. This other cluster unit 
becomes the new primary cluster unit.
If you can re-establish traffic flow through the interface (for example, if you re-connect 
a disconnected network cable) the interface rejoins the cluster. If Override Master is 
enabled for this FortiGate unit (see 
), this FortiGate unit 
becomes the primary unit in the cluster again.
Increase the priority of interfaces connected to higher priority networks or networks 
with more traffic. The monitor priority range is 0 to 512.
If a high priority interface on the primary cluster unit fails, one of the other units in the 
cluster becomes the new primary unit to provide better service to the high priority 
network. 
If a low priority interface fails on one cluster unit and a high priority interface fails on 
another cluster unit, a unit in the cluster with a working connection to the high priority 
interface would, if it becomes necessary to negotiate a new primary unit, be selected 
instead of a unit with a working connection to the low priority interface.
Note: Only monitor interfaces that are connected to networks.
Note: You can monitor physical interfaces, but not VLAN subinterfaces.