An introduction to the FGCP

Synchronizing the configuration (and settings that are not synchronized)

The FGCP uses a combination of incremental and periodic synchronization to make sure that the configuration of all cluster units is synchronized to that of the primary unit. This means that in most cases you only have to make a configuration change once to have it synchronized to all cluster units. This includes special configuration settings that include extra information (for example, 3rd party certificates, replacement message text files and graphics and so on).

Some configuration settings are not synchronized to support some aspects of FortiGate operation. The following settings are not synchronized among cluster units:

  • The FortiGate unit host name. Allows you to identify cluster units.
  • HA override.
  • HA device priority.
  • Virtual cluster 1 and Virtual cluster 2 device priorities.
  • The HA priority (ha-priority) setting for a ping server or dead gateway detection configuration.
  • The system interface settings of the FortiGate interface that becomes the HA reserved management interface.
  • The default route for the reserved management interface, set using the ha-mgmt-interface-gateway option of the config system ha command.
  • The dynamic weighted load balancing thresholds and high and low watermarks.

In addition licenses are not synchronized since FortiGate must be licensed separately. This includes FortiCloud activation, FortiClient, and FortiToken licensing, and entering a license key if you purchased more than 10 Virtual Domains (VDOMS).

This entry was posted in FortiOS 5.4 Handbook and tagged , on by .

About Mike

Michael Pruett, CISSP has a wide range of cyber-security and network engineering expertise. The plethora of vendors that resell hardware but have zero engineering knowledge resulting in the wrong hardware or configuration being deployed is a major pet peeve of Michael's. This site was started in an effort to spread information while providing the option of quality consulting services at a much lower price than Fortinet Professional Services. Owns PacketLlama.Com (Fortinet Hardware Sales) and Office Of The CISO, LLC (Cybersecurity consulting firm).

2 thoughts on “An introduction to the FGCP

  1. Danilo Arias

    Hi, thanks for sharing this information, however I wanted to make a query, that timer is only modified when there is a drop in monitored ports and does not increase over time is fixed? My question is why in his example I see that when the monitored port is reconnected, the teacher’s time is shorter in 136 seconds.

    Thanks and forgive my english but use google translate

    Reply

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.