Académique Documents
Professionnel Documents
Culture Documents
Search
Home > Online Help
> Chapter 16 - High Availability > FortiGate Session Life Support Protocol (FGSP) > Basic example
configuration
The following configuration example shows how to configure basic FGSP HA for the two peer
FortiGates shown below. The host names of peers are peer_1 and peer_2. Both peers are
configured with two virtual domains: root and vdom_1. All sessions processed by vdom_1 are
synchronized. The synchronization link interface is port3 which is in the root virtual domain. The IP
address of port3 on peer_1 is 10.10.10.1. The IP address of port3 on peer_2 is 10.10.10.2.
Also on both peers, port1 and port2 are added to vdom_1. On peer_1 the IP address of port1 is set
to 192.168.20.1 and the IP address of port2 is set to 172.110.20.1. On peer_2 the IP address of
port1 is set to 192.168.20.2 and the IP address of port2 is set to 172.110.20.2.
To configure FGSP HA
help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-high-availability-52/HA_standaloneConfigBasic.htm 1/3
22/08/18 Basic example configuration
Now that the FortiGates are connected and configured their configurations are
synchronized, so when you make a configuration change on one FortiGate it is
synchronized to the other one.
To add filters
You can add a filter to this basic configuration if you only want to synchronize some TCP sessions.
For example you can enter the following command to add a filter so that only HTTP sessions are
synchronized:
config system cluster-sync
edit 1
config filter
set service HTTP
end
end
You can also add a filter to control the source and destination addresses of the IPv4 packets that
are synchronized. For example you can enter the following command to add a filter so that only
sessions with source addresses in the range 10.10.10.100 to 10.10.10.200 are synchronized.
config system cluster-sync
edit 1
config filter
set srcaddr 10.10.10.100 10.10.10.200
end
end
You can also add a filter to control the source and destination addresses of the IPv6 packets that
are synchronized. For example you can enter the following command to add a filter so that only
sessions with destination addresses in the range 2001:db8:0:2::/64 are synchronized.
help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-high-availability-52/HA_standaloneConfigBasic.htm 2/3
22/08/18 Basic example configuration
config system cluster-sync
edit 1
config filter
set dstaddr6 2001:db8:0:2::/64
end
end
You enter the following command to synchronizationTCP sessions and set the synchronization link
(heartbeat device):
config system ha
set hbdev "port3" 50
set session-pickup enable
end
You enter the following command to add synchronization of UDP and ICMP sessions to this
configuration:
config system ha
set session-pickup enable
set session-pickup-connectionless enable
end
help.fortinet.com/fos50hlp/54/Content/FortiOS/fortigate-high-availability-52/HA_standaloneConfigBasic.htm 3/3