FortiGate 60F HA Cluster Build

แชร์
ฝัง
  • เผยแพร่เมื่อ 22 ก.ค. 2024
  • Let's try this again. This is a video about how to build an HA Cluster out of two FortiGate 60F's and 2 FortiSwitch 124F's.
    Buy Hardware: bit.ly/2QZVeqh
    Get Consulting: bit.ly/36FinSU
    My Other Projects:
    Office Of The CISO: bit.ly/3HGMH1o
    Packet Llama: bit.ly/3SEX3H4
    ###### SOCIAL LINKS ######
    Twitter: bit.ly/2WXiRAv
    Facebook: bit.ly/3eigz4D
    Instagram: bit.ly/3cZneAz
    ######################

ความคิดเห็น • 95

  • @darkhsu
    @darkhsu 2 ปีที่แล้ว +9

    Sounds like you have just been through a rough day. Cheer up Mike, we do like your videos. 😉

  • @RaviChinasamy
    @RaviChinasamy 2 ปีที่แล้ว +2

    Great to see that you are back at last. 😊

  • @clevtrev96
    @clevtrev96 ปีที่แล้ว +1

    The GOAT of FortiGate tutorials

  • @JoeyGarcia
    @JoeyGarcia 2 ปีที่แล้ว +2

    I have a pair of 500D and 300D FortiGate firewalls. Each pair are in HA. Definitely nice to have in the enterprise! I'm planning on introducing a pair of 1024D's and hopefully utilize MC-LAG

  • @drostoker
    @drostoker 2 ปีที่แล้ว

    Missed your videos. Looking forward to more in the near future.

  • @Darkk6969
    @Darkk6969 2 ปีที่แล้ว

    I have a pair of 601E at data center and corporate office. Both using HA setup. Although I am not using two Fortinet switches as HA. They're configured with a group of 4 ports VLANs to handle the WAN, LAN, VOIP and DMZ. It's not ideal but it makes moving the physical cables from one switch to another easy if one should die. I also have a third switch as a cold spare in the rack. I did the same thing with the WatchGuards before we moved to Fortinet products. Some ISP providers will give you two WAN drops for your HA setup.
    I agree on using active and passive in the HA cluster so you don't get into a pinch about performance if you need to do maintenance or one should die. There is one thing I did like about the WatchGuard's license policy for active / passive setup is that you only need live security on both devices. IPS and other licensed services are only required on the active device.

  • @Stingray7423
    @Stingray7423 2 ปีที่แล้ว

    Great as always!

  • @thewaterboy2013
    @thewaterboy2013 2 ปีที่แล้ว +1

    Thanks for this, Mike! Been very curious about the process for this for some time, but haven't had two forti's to do this with or had anyone to watch do this.

    • @MBNhub
      @MBNhub 2 ปีที่แล้ว

      you can do it forite vm

    • @thewaterboy2013
      @thewaterboy2013 2 ปีที่แล้ว

      @@MBNhub I hadn't looked into the vms for Forti, can you do them for free/evaluation for a lab setup?

  • @JasonsLabVideos
    @JasonsLabVideos 2 ปีที่แล้ว

    Wicked Video Mike, I did a HA setup too with my 61e's & pair of Cisco 24 port Switches :) Keep these videos coming !

  • @ivarutne6228
    @ivarutne6228 2 ปีที่แล้ว

    I love Fortigate because is extremely simple and extremely clear (best GUI) vs Palo Alto, SRX and so on. Team from Fortinet does good work.

  • @DeesoSaeed
    @DeesoSaeed 2 ปีที่แล้ว +1

    Recently configured two Fortigates 200Fin HA and two Fortiswitch 524D as core with MCLAG ICL, then a buch of 148Fs hanging from the latter for edge switching

  • @PabloMartinez-ds3og
    @PabloMartinez-ds3og 7 หลายเดือนก่อน +1

    Excellent tank you :)................

  • @portalend
    @portalend 2 ปีที่แล้ว +2

    Could you do a video on transitioning from static routing to dynamic routing like OSPF? I'm sure lots of people start out on entirely static routes then reach a scale where it becomes a pain to manage. I'm interested in the specifics on how the static routing will interact with the dynamic routes during the transition. Asking for a friend. 😉

  • @dgilvani
    @dgilvani 2 ปีที่แล้ว

    Tight! Tight!! TY

  • @quikmcw
    @quikmcw 2 ปีที่แล้ว

    Would like to make a request: Can you do a video setting up two AP's as a bridge, connecting two FSW together with fortilink and multiple vlan operation? This configuration is stumping the fortinet engineers!

  • @balla2172
    @balla2172 2 ปีที่แล้ว +1

    Gave you credit with corporate armor for the whole new network I just bought. I'd love to get another 601 so I could do ha but the budget just isn't there unfortunately

  • @ottawa29m
    @ottawa29m 2 ปีที่แล้ว +2

    1 - What options should we enable on the CLI to have a smooth failover?
    2 - Can you do a video on using a firewall as layer 2, and maybe touch on how this works in a cluster?

    • @databeestje
      @databeestje ปีที่แล้ว

      You can reset the HA timer, that will make it do a seamless failover.

  • @DhammikaNirodha
    @DhammikaNirodha ปีที่แล้ว

    Great

  • @gastonsalazar5052
    @gastonsalazar5052 2 ปีที่แล้ว

    gracias Genio!!!

  • @ashrafhelal9354
    @ashrafhelal9354 2 ปีที่แล้ว

    Thanks for doing those Videos, they are very good. i have a question about "port channel"
    can we create port channel two cables between the FortiGate1 going one cable to the Fortiswitch1 and the other fortiSwitch2: doing the same with FortiGate2?

  • @oralmolden1158
    @oralmolden1158 2 ปีที่แล้ว

    A while back I added MCLAG and you mentioned it, any plans to make a video on that. Also have a NAC deployment and was wondering if you had plans to make a video for pointers, maybe I missed something, maybe I missed a lot.

  • @lazzybug007
    @lazzybug007 5 หลายเดือนก่อน

    Well it all look easy for you... I never did a irl setup so far ..hope I will be successful 🤞.. being a fresher in this field without any support..it feels so difficult 😭

  • @mohamedabdullahi3665
    @mohamedabdullahi3665 ปีที่แล้ว

    thanks well legend

  • @terrykilpatrick5799
    @terrykilpatrick5799 2 ปีที่แล้ว +1

    I find your content very helpful, the only thing that would help is if you could speak a bit more loudly or add a bit more volume to the audio for sometimes it's difficult to understand clearly what you are saying. Thanks and keep them coming.👍

  • @gobofraggel7383
    @gobofraggel7383 2 ปีที่แล้ว

    The only firewall I know is Sophos XG and now XGS. I configured HA for a client that is a 24/7 company with 7 warehouses and it was easy and it worked as expected. I have always been intrigued by FortiGate. Which is better?

  • @dirkmare6445
    @dirkmare6445 2 ปีที่แล้ว

    Hi Mike, new to fortigate fw I recently watched your video about firmware upgrades and your three rules.. I Would really like to use video content filtering but its only included in V7 and not V6.4.6
    So I guess my question is for new out of the box setup is it save/advisable to upgrade to newer firmware's and when do you bite the bullet to do upgrades in production?
    EXAMPLE: GA minus 2 versions
    Thanks

  • @dergarmark7189
    @dergarmark7189 2 ปีที่แล้ว +1

    Good video! Could you please make a video of a deep dive into the HA options such as monitoring ports and manual failover and failback? Maybe you could show HA status in the cli too. You could show how an firmware update works with HA.

    • @mrStarcKbe
      @mrStarcKbe 2 ปีที่แล้ว

      Sometimes is happens that your cluster isn’t in sync through the gui. The following command through cli can help you with that check “diag sys ha checksum cluster”. This way you are certain that the cluster is ok. You can setup more HB interfaces and perhapse a dedicated one for the tcp sessions to failover. Then you have that group id which I highly recommend to change if the customer has multiple Fortigate clusters. At last the command “set override enable” and “set override-wait-time 300” so the cluster will automatically fallback to the primary device after a failover. Not going into details like changing the ether packets. 👍

    • @adipapaianus5723
      @adipapaianus5723 ปีที่แล้ว

      @@mrStarcKbe You are 110% right! Every HA cluster should have "set group-id XY" configured. I had a situation in the past where WAN1 was constantly flapping due to another Fortigate HA cluster on the WAN subnet! It was like crazy! Once I have configured group-id pain went away and HA is running rock solid for the past 3 years on 6.2.x release.

  • @jamesmyers777
    @jamesmyers777 ปีที่แล้ว

    Would have been good to discuss session pickup more, what types of sessions can and can't be failed over and other ideas like that. I would also like to know more about active active, any chance of ajother HA video mate?

  • @ian230187
    @ian230187 ปีที่แล้ว

    Hey...have a doubt here....
    Did you get a chance to check the CAM LAN switch where the secondary ports sre connected?
    They do not populate physical mac address of the Fortigate nic.... wanted to understand the concept

  • @ashrafhelal9354
    @ashrafhelal9354 2 ปีที่แล้ว

    13:03 i was wondering, if there isn't a DHCP, how they are going to get a new management IP? and can we do it through cli?

  • @zSnowFlakesTV
    @zSnowFlakesTV 2 ปีที่แล้ว

    Guru, I'm having a really hard time finding a way to build a whitelist in fortiOS 7.0.2, could you make a video talking about white and blacklist rules? how to build it properly? I've been researching reddit and forti cookbock but I just can't figure out what I'm doing wrong. love your videos I learned a lot from you keep it up !!

  • @boyd8871
    @boyd8871 4 หลายเดือนก่อน

    Hello, can you explain more why the frotigate is degraded when primary/slave failed in active-active setup?

  • @MladenMarinov
    @MladenMarinov 2 ปีที่แล้ว

    Hi, I like you lectures.
    Unfortunately I have problem you did not review - passing the multicast traffic from the provider to STB.
    Can I contact you to guide me about this?

  • @serlegar
    @serlegar 2 ปีที่แล้ว

    That mac address story remind me of that day when I installed Fortigate cluster in a data center where another client had already another Fortigate cluster. We were both connected to the same datacenter internet provider switch and obviously spoofing the same mac address...

    • @FortinetGuru
      @FortinetGuru  2 ปีที่แล้ว +3

      Yeah. The key around that is to change the HA group ID to a different number.

    • @mrStarcKbe
      @mrStarcKbe 2 ปีที่แล้ว

      @@FortinetGuru true

    • @adipapaianus5723
      @adipapaianus5723 ปีที่แล้ว

      same story here ... always set group-id for a HA cluster.

  • @pavelbrusnicky2723
    @pavelbrusnicky2723 2 ปีที่แล้ว

    How about fortigate vs multiple switches session? Thanks.

  • @dmitriykott769
    @dmitriykott769 2 ปีที่แล้ว

    Hellow, please make review about new version fortios 7.2!

  • @askmethod
    @askmethod 26 วันที่ผ่านมา

    13:03 from where did u bring floating IP

  • @RichardDePas
    @RichardDePas 2 ปีที่แล้ว

    Set this up about 6 months ago with 101F Frotigates and 124F FortiSwitches. Opted for the FortiLink Split interfaces. Probably more of a pain than I needed to go through. Had one switch drop offline and needed a hard reboot to get it going again. Never did find the root cause.

    • @FortinetGuru
      @FortinetGuru  2 ปีที่แล้ว

      Yeah, I've had that happen as well.

    • @RichardDePas
      @RichardDePas 2 ปีที่แล้ว

      @@FortinetGuru Any clue why it happened? Or is that a bug in 7.0 code?

  • @knithiyanandhan
    @knithiyanandhan 2 ปีที่แล้ว

    Need a Help: I need to allow port 3306 from outside company one particular IP address?

  • @salvadorseekatzrisquez2947
    @salvadorseekatzrisquez2947 2 ปีที่แล้ว

    My experience, is that HA makes the maintenance window longer because the delay after one reboots we need to wait for them to Sync again. Depending on the customer some connections to the Internet will break during HA so for some customer its more outages than less, I am not advocating against redundancy, it's def. nice to have. But a single reboot for upgrade. Maybe Fortinet could improve the way they upgrade. Also I noticed that this on Active/Passive. Active/Active is not really a fact, I have tried to work with Fortinet Support and they have said that it doesn't really work to avoid outages.

    • @mrStarcKbe
      @mrStarcKbe 2 ปีที่แล้ว

      True on the A-A part, but not completely true the HA part. You can set it to override disable so it won’t switch back to the primary unit. This way you can initiate it your self. The first failover will always be faster then a single unit. 👍

  • @cankitchourasia
    @cankitchourasia 2 ปีที่แล้ว

    I see you did not select the "Monitor Interface" option under HA. Curious to know how will FWs detect failover scenario.

    • @FortinetGuru
      @FortinetGuru  2 ปีที่แล้ว

      Once this foetigate cluster is installed on location I will pick the monitored interfaces based on need. 99% chance I will use the fortilink aggregate and the wan1 port.

  • @frankperera3885
    @frankperera3885 2 ปีที่แล้ว

    can someone explain how to do the process mentioned in 12:40 ?

  • @headdstrong983
    @headdstrong983 2 ปีที่แล้ว

    Hello from Russia.
    btw recently i configured Fortigate 200 mode with HA mode in prodaction.

  • @allferryrocha2698
    @allferryrocha2698 2 ปีที่แล้ว

    Hey Mike, good time for you to make a video on how to block Log4J on Fortigate FW.

    • @mrStarcKbe
      @mrStarcKbe 2 ปีที่แล้ว

      Use IPS signatures and use them as they should be used on “severity” level. So use the IPS filter to block medium,high and critical severity levels. Put them on ALL policy’s! Also on internal once so a breached client can’t use that a signature (medium,high or cricital). For traffic coming from internet use that same IPS filter. And for servers where you can use SSL Server protection put that on too so you can inspect https traffic too.

  • @renhe108
    @renhe108 2 ปีที่แล้ว

    Do you consider to set monitor port in HA settings? if the port down, the failover will happen right away.

    • @FortinetGuru
      @FortinetGuru  2 ปีที่แล้ว

      That is correct. You would configure monitoring of the port for physical outages. Link monitors will assist if the upstream link is "green" but not passing traffic.

  • @billwoodall562
    @billwoodall562 2 ปีที่แล้ว

    Good video, I do have a question. Can you HA an existing firewall? I have a 201F and bought a backup unit.

    • @FortinetGuru
      @FortinetGuru  2 ปีที่แล้ว

      Sure can

    • @billwoodall562
      @billwoodall562 2 ปีที่แล้ว

      @@FortinetGuru I am assuming the same process just make the primary firewall the master first?

  • @IxTapewormxI
    @IxTapewormxI 2 ปีที่แล้ว

    Hope your doing alright Chuck its been a few months. Can you show us how to configure a FortiSwitch 224E in Stand alone mode? I've been having issues getting mine to work correctly with the management vlan.

    • @FortinetGuru
      @FortinetGuru  2 ปีที่แล้ว

      I am alive, but in the famous words of Big Hero 6....I am not fast.... haha

  • @rodneyaltamera4057
    @rodneyaltamera4057 2 ปีที่แล้ว

    HI Fortinet Guru I have a question. I have a setup that is in HA Cluster (Active-Active). The problem when I update the firmware both Firewalls will loose connection and restart. I was expecting that the Primary will be updated first, then the backup will be next. Can you give me any advise what I am doing wrong. Thanks

    • @mrStarcKbe
      @mrStarcKbe 2 ปีที่แล้ว

      Normally you login on the primary device so the upgrade command is send to the primary device. Then it checks the checksum and if it’s good it will send the update to the secondary device. It them will start updating. In an active/active the load balancing is turned of so all traffic will be route towards primary device.

  • @abdomordy6935
    @abdomordy6935 ปีที่แล้ว

    how can i deploy Fortigate FW HA active-active on AWS in muli AZ environment with autoscalling?

  • @shanegreentree7851
    @shanegreentree7851 8 หลายเดือนก่อน

    hi. I am looking at buying two 60f, can I use unifi switch to set up ha

  • @MuhammadWaqas-fq3yg
    @MuhammadWaqas-fq3yg 2 ปีที่แล้ว

    Can we test the HA Cluster on EVE-NG ? Did any one try it ?

  • @salvadorseekatzrisquez2947
    @salvadorseekatzrisquez2947 2 ปีที่แล้ว

    I like the sound of your keyboard and mouse, what do you use?

  • @hennessy6996
    @hennessy6996 2 ปีที่แล้ว

    Hi, do you usually do Central NAT?
    Is your preference Flow-based inspection?

    • @FortinetGuru
      @FortinetGuru  2 ปีที่แล้ว

      Majority of my firewalls are done with UTM Profile mode and standard NAT. I have started doing more and more with NGFW Policy mode and Central NAT (especially conversions from PAN devices)

    • @rosatechnocrat
      @rosatechnocrat 2 ปีที่แล้ว

      From a working mode or faster traffic Flow mode is better , But in flow mode some the features are not allowed as the in flow mode connection is not terminated on Fortigate. But If you want deep inspection then Proxy mode is better.

  • @uneeds2122
    @uneeds2122 2 ปีที่แล้ว

    Hello Fortinet Guru
    just one question please
    I have fortigate which i made web filter on it
    but some user uses VPN to passthrow web filter
    how I can fix this, what the method to solve this
    thank you

    • @FortinetGuru
      @FortinetGuru  2 ปีที่แล้ว +1

      Block vpn access at the application level.

  • @amro_hadi
    @amro_hadi 2 ปีที่แล้ว

    hey, fortinet Guru, do you have any videos for VDOMs?

    • @rosatechnocrat
      @rosatechnocrat 2 ปีที่แล้ว

      What kind of videos you need For Vdoms ..

    • @amro_hadi
      @amro_hadi ปีที่แล้ว

      @@rosatechnocrat What are Vdoms for start, what are the use cases when Vdoms can be useful and how the traffic flows in Vdoms.

  • @Firecross666
    @Firecross666 2 ปีที่แล้ว

    Do you have any interest or experience in configuring FortiWeb?

  • @rikerud
    @rikerud 2 ปีที่แล้ว

    What equipment are you running your self this days?

    • @FortinetGuru
      @FortinetGuru  2 ปีที่แล้ว

      Still cruising on an 80e-poe at the house

    • @rikerud
      @rikerud 2 ปีที่แล้ว

      @@FortinetGuru using Forti AP's with it as well?

  • @thebocop
    @thebocop ปีที่แล้ว

    Confused on how you have this hooked up to the switches...

    • @FortinetGuru
      @FortinetGuru  ปีที่แล้ว

      In what way? A of each FortiGate goes to each Switch and B of each FortiGate does the same. Split link on the Fortilink makes it full mesh. Other options are A of each FortiGate to switch 1 and B of each FortiGate to switch 2 with split-fortilink off.

    • @thebocop
      @thebocop ปีที่แล้ว

      @@FortinetGuru I found out I had to delete a few interfaces to make them available for the HA ports on the 60F.... (4 and 5)

  • @raphaelfigueredo5524
    @raphaelfigueredo5524 10 หลายเดือนก่อน

    deus do fortinet

  • @xephael3485
    @xephael3485 2 ปีที่แล้ว

    1:35 Fortigates use HSRP? Don't use Cisco trash... VRRP, etc.

  • @ITS-yk5ky
    @ITS-yk5ky หลายเดือนก่อน

    The part about the device priority is wrong. The lower the number, the higher the priority.

    • @FortinetGuru
      @FortinetGuru  หลายเดือนก่อน

      No. In HA higher priority wins. In routing, lower priority wins.

  • @IsmailNuzaifKokky
    @IsmailNuzaifKokky 2 ปีที่แล้ว

    .

  • @khalil4826
    @khalil4826 ปีที่แล้ว

    bla bla bla ...

  • @waqaskhan-cx5dx
    @waqaskhan-cx5dx 2 ปีที่แล้ว

    I have to two fortigate firwall 201 f and want to configure cluster HA. And Also have to Wan connection. I need a little help with that. Can you please share your email address so we can discuss it sir.