Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ErrantOsi
New Contributor III

SNMP Monitoring both Firewalls seperate in a VDOM enabled HA-Cluster

Hello fellow Fortinet people. We have a new Fortigate Cluster (AP) with VDOMs enabled (our first Cluster with VDOM config). Now of course we want to monitore both firewalls seperately. Until now we always used the IP addresses of the dedicated management interfaces. However I just learned the following two limitations of Fortigates:

«To get SNMP working with VDOM enabled: Make sure that the interface where the SNMP collector connects to is part of the management VDOM.»
«Note: Dedicated management ports on a HA Cluster will not be part of any VDOM.»

Now from my understanding this means we cannot use the dedicated management interfaces (which are excluded from the HA). Does anyone of you has the same config and if yes, how do you monitor both firewall seperate?

1 Solution
saleha
Staff
Staff

Hello,

 

Thank you for reaching out. If you want to monitor the secondary member of the cluster I believe you will need ha direct and reserving management port. I recommend checking out the article link below for recommendations:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Adding-Secondary-SNMP-server-on-FortiGate-...

 

Thank you,

Ahmed Saleh

View solution in original post

2 REPLIES 2
saleha
Staff
Staff

Hello,

 

Thank you for reaching out. If you want to monitor the secondary member of the cluster I believe you will need ha direct and reserving management port. I recommend checking out the article link below for recommendations:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Adding-Secondary-SNMP-server-on-FortiGate-...

 

Thank you,

Ahmed Saleh

ErrantOsi
New Contributor III

Yeah we had to enable the HA-Direct option to fully use all services.

Labels
Top Kudoed Authors