High Availability Flashcards
(42 cards)
How many FTG’s can be put in a cluster?
two to four
What is synchronized in an HA Cluster?
Configruation, session info, FIB entries, FortiGuard definitions,
Do passive members in a A-P HA cluster process traffic?
No, only start forwarding in the event of a fail over.
How does active-active work?
The primary FTG can distribute sessions to other cluster members
What is FGCP?
FortiGate Clustering Protocol
What does FGCP do?
Used for member discovery, primary election, data sync, member health monitoring.
What is frame type 8890/1 in H/A Heartbeats
0x8890 is NAT mode 0x8891 is transparent mode
What is frame type 8893 in H/A Heartbeats
Data synchronization, logging and cli management
For HA what does inner packet type TCP/UDP 703 used for?
Data Sync
For HA what does inner packet type TCP 700 used for?
Logging and email alerts
For HA what does inner packet type TCP 22 used for?
CLI Management
What can trigger an HA Failover
Dead member, Failed link, Failed remote link, high memory usage, failed SSD, admin triggered
What must match in order to form an HA Cluster?
Firmware version,
Model (virtual or physical)
Licensing
Hard drive config (size, partitions)
Operating mode: NAT or transparent
What happens if the licensing models are different in HA Clusters?
The lowest level of license in common is used.
What must match from an HA Settings perspective?
Group ID, group name, password and interface settings
Should you place all heart beat interfaces in the same broadcast domain?
Yes
What is the Election process when override is disabled
of connected interfaces
HA Uptime
Priority (highest)
Lowest serial number
what does diagnose sys ha reset-uptime do?
Reset HA uptime to 0]
What is the primary fortunate election with override enabled?
of connected interfaces
Priority (highest)
HA Uptime
Lowest serial number
The highest priority means you can specify a FTG that will always become the primary even after it recovers from a failover.
What operational data does the primary FTG synch
Some config settings
FIB entries
DHCP lease
ARP table
FortiGuard definitions
IPsec SA’s
Sessions (must be enabled)
What is the heartbeat IP address assignment for the highest serial number? second?
169.254.0.1 for first
169.254.0.2 for the second
When do heartbeat IP address change?
When a device joins or leaves the cluster
What port must you use for heartbeats?
physical only
Are heartbeat interfaces used for user traffic?
no