Skip to main content
Question

Fortinet Firewall cluster onboarding

  • December 10, 2024
  • 2 replies
  • 233 views

Hello Beekepers 

I have a question with regard to Fortinet Firewall onboarding. We have Firewalls in HA that have 1 active and 1 passive device using a single IP  so basically these devices are clustered. Can Password safe onboard the devices that utilize a single IP. We found that we can only onboard the active node and not the passive node. Has anyone seen this before and how did you onboard

2 replies

  • BeyondTrust Employee
  • December 11, 2024

Something to note; currently Password Safe does not support TACAS account

 

Password Safe identifies a system using IP or a DNS name. If the Fortinet device is a HA pair sharing a VIP then Password Safe can only onboard the IP/DNS name. Password Safe doesn’t have the capabilities to manage clustering/HA of a managed system. When onboarding the node was it able to rotate the password? If the password rotation is successful should the Firewall perform the password sync between the Active/Passive node? 


  • Author
  • Apprentice
  • December 19, 2024

Thank you Howard