High Availability Flashcards
What does FortiGate use to discover members, elect the primary FortiGate, and monitor the health of members?
FortiGate Clustering Protocol (FGCP)
What are the two HA operation modes?
- Active-active
- Active-passive
In active-passive mode, how does the secondary FortiGate device behave?
- Passive, monitors the status of the primary device
- Takes over primary role if a problem is detected on the primary FortiGate
What is the difference between active-passive mode and active-active mode?
- In active-active, all cluster members can process traffic
- The primary FortiGate can distribute supported sessions to the secondary devices
What are the requirements to form an HA cluster?
- Members must have the same
- Model
- Firmware version
- Licensing (if different, uses the lower)
- Hard drive configuration
- Operating mode
What settings should you configure the same on each HA cluster member?
- Group ID
- Group name
- Password
- Heartbeat interface settings
What are some best practices to apply when configuring HA clusters?
- Configure at least two heartbeat interfaces for redundancy
- Try to place all heartbeat interfaces in the same broadcast domain, or directly connected if only two
How does the primary FortiGate election process work?
- Compares number of monitored interfaces that are up
- Compares HA uptime of each member
- Highest priority
- Highest serial number
What happens when HA override is disabled?
- HA uptime has precedence over the priority setting
- If you must manually fail over to a secondary device, you can do so by reducing the HA uptime of the primary FortiGate by running diagnose sys ha reset-uptime
What is a task the primary FortiGate takes on only in active-active mode?
Distributes sessions to secondary members
What is a task performed by the secondary FortiGate only in active-active mode?
Processes traffic distributed by the primary
How does FGCP assign heartbeat IP addresses?
- Automatically based on the serial number of each device
- 169.254.0.1 gets assigned to the device with the highest SN
What are characteristics of heartbeat IP addresse?
- Non-routable
- Only used for FGCP operations
- HA cluster uses them to distinguish cluster members and synchronize data
What is good practice when configuring heartbeat interfaces?
- Must configure at least one port as a heartbeat interface, and can only use physical interfaces
- Heartbeat traffic should be on a dedicated VLAN
What must be configured for link failover to work?
One or more monitored interfaces