High Availability – FortiManager 5.2

General FortiManager HA configuration steps

The following procedures assume that you are starting with four FortiManager units running the same firmware build and are set to the factory default configuration. The primary unit and the first backup unit are connected to the same network. The second backup units is connected to a remote network and communicates with the primary unit over the

Internet.

  1. Configure the FortiManager units for HA operation:

Configuring        options

  • Configure the primary unit.
  • Configure the backup units.
  1. Change the network configuration so that the remote backup unit and the primary unit can communicate with each other.
  2. Connect the units to their networks.
  3. Add basic configuration settings to the cluster:
    • Add a password for the admin administrative account. l Change the IP address and netmask of the port1 interface. l Add a default route.

Web-based Manager configuration steps

Use the following procedures to configure the FortiManager units for HA operation from the FortiManager unit Web-based Manager. Sample configuration settings are also shown.

To configure the primary unit for HA operation:

  1. Connect to the primary unit Web-based Manager.
  2. Go to System Settings > HA.
  3. Configure HA settings.

Example HA master configuration:

Operation Mode Master
Peer IP 172.20.120.23
Peer SN <serial_number>
Peer IP 192.268.34.23
Peer SN <serial_number>
Cluster ID 15
Group Password password
Heartbeat Interval 5 (Keep the default setting.)
Failover Threshold 3 (Keep the default setting.)
  1. Select Apply.
  2. Power off the primary unit.

To configure the backup unit on the same network for HA operation:

  1. Connect to the backup unit Web-based Manager.
  2. Go to System Settings > HA.
  3. Configure HA settings.

Example local backup configuration:

Operation Mode Slave
Priority 5 (Keep the default setting.)
Peer IP 172.20.120.45
Peer SN <serial_number>
Cluster ID 15
Group Password password
Heartbeat Interval 5 (Keep the default setting.)
Failover Threshold 3 (Keep the default setting.)
  1. Select Apply.
  2. Power off the backup unit.
This entry was posted in Administration Guides, FortiManager and tagged , on by .

About Mike

Michael Pruett, CISSP has a wide range of cyber-security and network engineering expertise. The plethora of vendors that resell hardware but have zero engineering knowledge resulting in the wrong hardware or configuration being deployed is a major pet peeve of Michael's. This site was started in an effort to spread information while providing the option of quality consulting services at a much lower price than Fortinet Professional Services. Owns PacketLlama.Com (Fortinet Hardware Sales) and Office Of The CISO, LLC (Cybersecurity consulting firm).

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.