NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
yagyu
Feb 23, 2021Aspirant
GS716Tv3 Ha SETUP
Hi!
I want to set up HA with fortigate firewalls like:
switch - fw - switch
internet ---> | | | --> LAN
switch - fw - switch
and appropriate interconnections between the switches -> is this possible with the GS716TV3?
can I get some config examples?
Trying to eliminate the switches as single points of failure
thanks for looking
Model: GS716Tv3|ProSafe 16 ports Gigabit Smart switch
5 Replies
- JohnC_VNETGEAR Employee Retired
Welcome to our community! :)
May I know what do you want to achieve here? The firewall should be the one that is connected to the internet first before the switch. Do you have a multi-WAN setup?
Regards,
John
NETGEAR Community Team
- yagyuAspirant
Hi John
I want to have redundant firewalls in case one dies it's not a SPOF.
To achieve this I need a switch to aggregate my 2 firewalls and 1 internet circuit line.
Just like this contraption:
To go one better I want 2 switches in HA too if I can.
Matt
- schumakuGuru - Experienced User
yagyu wrote:To go one better I want 2 switches in HA too if I can.
And a little assistant changing the link to the Internet line in the failure case?
This is what we implement in basic HA environments - you can add two additional switches on the Internet side of you desire:
- schumakuGuru - Experienced User
yagyu wrote:I want to set up HA with fortigate firewalls like:
switch - fw - switch
internet ---> | | | --> LAN
switch - fw - switch
Yes, with Internet connections providing plain IP on the WAN connection (no PPTP, no PPPoE, ...), and permitting you don't expect e.g some L3 features like routing or VRRP, this can be configured with any switch.
General advise: Consult with your firewall vendor for HA/failover/cluster configurtion switch requirements.
JohnC_V no Multi-WAN and so on required for such a HA set-up. HA capable firewalls from Fortigate, Sonicwall, or ZyXEL (this isn't consumer ****) are supporting virtual MAC addresses. FMI:HA Cluster virtual MAC addresses
- schumakuGuru - Experienced User
Curious how you intend to connect what akes up the "Internet" at your site - typically a device with just one port - should be connected in a full HA set-up.
Related Content
NETGEAR Academy
Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!