How interesting! You have selected the same combo of firewalls, and placed them in the same order as I have... but on my go-live I keep having spanning tree issues (I think) that are taking too long a time to resolve and that prevents my go-live and I have to back out 😞 My fortigates are slightly different, I think, as I am told they are an active active cluster in transparent mode, the thinking being should benefit from the additional processing power, at the expense of a few discontinued sessions if there were to be a failure. We also want to do WAN/ISP + VPN tunnel load balancing to complete the redundancy in our network... My interconnections at the wiring level are exactly as you proposed in your diagram... Would you be able to post a diagram of your functional solution once implemented? Thanks a million, Doug Coleman
... View more