FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Not applicable
Article Id 190470

Article

Description

HA limitations of FortiGate interfaces that are switches.

Platform

All FortiOS

  • The internal switch interface of all models (hardware and software)

HA Monitor Priorities

FortiGate models that are configured with internal software or hardware switch do not support interface monitoring (also called port monitoring) and link failover for the switch interface.

HA Heartbeat Devices

FortiGate interfaces that contain an internal switch do support configuring the switch interface as a HA heartbeat device. However this configuration is not recommended for two reasons:

  • For security reasons and to save network bandwidth you should keep HA heartbeat traffic off of your internal network
  • Heartbeat packets may be lost if the switch interface is processing high volumes of traffic. Loosing heartbeat packets may lead to unnecessary and repeated failovers.

 

Contributors