12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

HA<br />

System Config<br />

Group Name Add a name to identify the cluster. The maximum group name length is 7<br />

characters. The group name must be the same for all cluster units<br />

before the cluster units can form a cluster. After a cluster is operating<br />

you can change the group name. The group name change is<br />

synchronized to all cluster units.<br />

The default group name is FGT-HA. You can accept the default group<br />

name when first configuring a cluster. When the cluster is operating you<br />

can change the group name if required. Two clusters on the same<br />

network cannot have the same group name.<br />

Password<br />

Enable Session<br />

pickup<br />

Port Monitor<br />

Heartbeat<br />

Interface<br />

VDOM<br />

partitioning<br />

Add a password to identify the cluster. The maximum password length is<br />

15 characters. The password must be the same for all cluster units<br />

before the cluster units can form a cluster.<br />

The default is no password. You can accept the default when first<br />

configuring a cluster. When the cluster is operating you can add a<br />

password if required. Two clusters on the same network must have<br />

different passwords.<br />

Enable session pickup so that if the primary unit fails, all sessions are<br />

picked up by the cluster unit that be<strong>com</strong>es the new primary unit.<br />

Session pickup is disabled by default. You can accept the default setting<br />

for session pickup and then chose to enable session pickup after the<br />

cluster is operating.<br />

Enable or disable monitoring <strong>FortiGate</strong> interfaces to verify that the<br />

monitored interfaces are functioning properly and connected to their<br />

networks.<br />

If a monitored interface fails or is disconnected from its network the<br />

interface leaves the cluster and a link failover occurs. The link failover<br />

causes the cluster to reroute the traffic being processed by that interface<br />

to the same interface of another cluster unit that still has a connection to<br />

the network. This other cluster unit be<strong>com</strong>es the new primary unit.<br />

Port monitoring is disabled by default. Leave port monitoring disabled<br />

until the cluster is operating and then only enable port monitoring for<br />

connected interfaces.<br />

You can monitor up to 16 interfaces. This limit only applies to <strong>FortiGate</strong><br />

units with more than 16 physical interfaces.<br />

Enable or disable HA heartbeat <strong>com</strong>munication for each interface in the<br />

cluster and set the heartbeat interface priority. The heartbeat interface<br />

with the highest priority processes all heartbeat traffic. If two or more<br />

heartbeat interfaces have the same priority, the heartbeat interface that<br />

is highest in the interface list processes all heartbeat traffic.<br />

The default heartbeat interface configuration is different for each<br />

<strong>FortiGate</strong> but usually sets the priority of two heartbeat interfaces to 50.<br />

You can accept the default heartbeat interface configuration if one or<br />

both of the default heartbeat interfaces are connected.<br />

The heartbeat interface priority range is 0 to 512. The default priority<br />

when you select a new heartbeat interface is 0.<br />

You must select at least one heartbeat interface. If heartbeat<br />

<strong>com</strong>munication is interrupted the cluster stops processing traffic. For<br />

more information about configuring heartbeat interfaces see the<br />

<strong>FortiGate</strong> HA <strong>Guide</strong>.<br />

You can select up to 8 heartbeat interfaces. This limit only applies to<br />

<strong>FortiGate</strong> units with more than 8 physical interfaces.<br />

If you are configuring virtual clustering you can select the virtual<br />

domains to be in virtual cluster 1 and the virtual domains to be in virtual<br />

cluster 2. The root virtual domain must always be in virtual cluster 1. For<br />

more information about configuring VDOM partitioning see the <strong>FortiGate</strong><br />

HA <strong>Guide</strong>.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

138 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!