Forum Discussion
Setting up LACP between the F5 machine and two firewalls in cluster
Thank you guys.
We're not looking to purchase new another for clustering the F5. Only another firewall for clustering the firewall. So evetually we'll have one F5 and two fortigates in cluster.
As I understood from fortinet KBs, a fortigate in cluster should share a VMAC in case of failover
So basically the F5 will continue to send the traffic to same primary member if the F5 can handle the gratuitous ARP from the Fortigate cluster firewalls.
I only was hoping if someone have same design and can confirm this to us. 🙂
- Jun 06, 2023
Hi ac89live ,
Bigip is same as Fortigate firewall if you configure the MAC address masquraded feature on bigip traffic group ,
From my perspective bigip will NOT send traffic to the Failed FW node , as the second FW unit will advertise gARP as you said and this gARP will make Bigip to detect the failover that happen between Firewalls units.
> Because of both of FWs shares same vMAC address the gARP will NOT update the ARP cache table ( IP & MAC ) but gARP updates CAM table ( MAC and Ports ) so from my perspective , Bigip will detect the failover quickly and forward traffic in the correct path to the ACTIVE FW unit.
For That I will Need one of F5 Experts can validate my answer or they can adjust it for us to get the most correct answer.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com