M5500-AC-I Singal Deployment with 2 upstream Forti FW and 2 downstream Cisco FW

Newbie973945 Lv1Posted Jun-06-2025 10:30

Hi All

We are trying to implement a solution to make the CX perimeter FW's and Internal FW redundant. currently its not redundant. customer is only using 1 M5500-AC-I unit in bridge mode between core SW and FW. Is there a way we can configure the single  M5500-AC-I support the new topology.

FW A -------           --------FW B
                     Sangfor
FW C -------            --------FW D

Appreciate any input.

Thank you

Sanjaya

mantasha has solved this question and earned 10 coins.

Posting a reply earns you 2 coins. An accepted reply earns you 20 coins and another 10 coins for replying within 10 minutes. (Expired) What is Coin?

Enter your mobile phone number and company name for better service. Go

ngle M5500-AC-I cannot support the redundant firewall topology. To achieve proper redundancy with FW A/B and FW C/D, you need to deploy **two M5500-AC-I units in High Availability (HA) mode**. This will eliminate the single point of failure and allow seamless traffic failover between firewalls.
Is this answer helpful?
Humayun Ahmed Lv3Posted Jun-10-2025 12:28
  
you can reconfigure your existing M5500-AC-I in bridge mode to logically support separate connectivity for the external (FW A/B) and internal (FW C/D) firewall pairs using its multiple interfaces or VLAN capabilities, this setup will not eliminate the single point of failure. For full redundancy and resiliency, you would eventually need to implement a secondary unit in a high availability configuration if the platform supports clustering.
Newbie996439 Posted Jun-10-2025 18:58
  
Use Virtual Router Redundancy Protocol (VRRP) or Hot Standby Router Protocol (HSRP) to create a virtual IP address that both firewalls can share. This way, if one firewall fails, the other can take over without disruption.
Sanjaya Lv1Posted Jun-11-2025 09:40
  
Thank you Team.

Will check your suggestions and update you .

Thank you very much
Syed ShahMir Lv1Posted Jun-16-2025 14:14
  
A single M5500-AC-I cannot support the redundant firewall topology. To achieve proper redundancy with FW A/B and FW C/D, you need to deploy **two M5500-AC-I units in High Availability (HA) mode**. This will eliminate the single point of failure and allow seamless traffic failover between firewalls.
Ayra Posted Jun-16-2025 22:40
  
Using its multiple interfaces or VLAN capabilities, you can logically support separate connectivity for the external (FW A/B) and internal (FW C/D) firewall pairs by reconfiguring your existing M5500-AC-I in bridge mode. However, this setup will not eliminate the single point of failure; if the platform supports clustering, you will eventually need to implement a secondary unit in a high availability configuration for complete redundancy and resiliency.
mantasha Lv2Posted Jun-18-2025 03:30
  
ngle M5500-AC-I cannot support the redundant firewall topology. To achieve proper redundancy with FW A/B and FW C/D, you need to deploy **two M5500-AC-I units in High Availability (HA) mode**. This will eliminate the single point of failure and allow seamless traffic failover between firewalls.

I Can Help:

Change

Moderator on This Board

910
182
94

Started Topics

Followers

Follow

Board Leaders