2.5.4 Ensure High Availability Group-ID is configured

Information

Ensure that FortiGate High Availability (HA) configuration has non-default \\"Group-ID\\"

High Availability (HA) allows a FortiGate cluster to float a virtual MAC address between devices to minimize downtime if there is a failover event. This Virtual MAC address is generated using the GROUP-ID so to prevent possible duplicate MAC addresses on Layer 2 of the network configuring a non-default Group-ID is needed.

Solution

To modify High Availability (HA) Group-ID

From the CLI:

FGT1 # config system ha
FGT1 (ha) # set group-id 10
FGT1 (ha) # end
FGT1 #

The Group ID can be any integer value from 0-1023

From the GUI:

1. System > HA
2. Select Primary device and either double click or single click and select \\"Edit\\"
3. Under Cluster Settings enter a value in the \\"Group ID\\"
4. Click OK to apply

The Group ID can be any integer value from 0-1023

Impact:

Not modifying the Group-ID attribute in HA could allow a duplicate MAC address from another default FortiGate having HA configured which can cause problems if they are both within the same network

See Also

https://workbench.cisecurity.org/benchmarks/24708

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-13(5)

Plugin: FortiGate

Control ID: 810d566f4ce5e6e768315991dea23b41aa47b3446c8abf97a9c06f5c2e9dd0ef