56 01-28006-0024-20041026 Fortinet Inc.
Configuring FortiGate units for HA using the CLI High availability installation
Inserting an HA cluster into your network temporarily interrupts communications on
the network because new physical connections are being made to route traffic through
the cluster. Also, starting the cluster interrupts network traffic until the individual
FortiGate units in the cluster are functioning and the cluster completes negotiation.
Cluster negotiation normally takes just a few seconds. During system startup and
negotiation all network traffic is dropped.
To connect the cluster
1 Connect the cluster units:
• Connect the internal interfaces of each FortiGate unit to a switch or hub connected
to your internal network.
• Connect the external interfaces of each FortiGate unit to a switch or hub connected
to your external network.
• Optionally connect the DMZ interfaces of each FortiGate unit to a switch or hub
connected to your DMZ network.
• Optionally connect ports 1 to 4 of each FortiGate unit to switches or hubs
connected to other networks.
• Connect the HA interfaces of the FortiGate units to another switch or hub. By
default the HA interfaces are used for HA heartbeat communication. These
interfaces should be connected together for the HA cluster to function.