HA behind a FW. Fortigate

Hi!

i have one problem in this infraestructure;

HA (running in a raspberry) doesn’t find Xiaomi GW. There is no deny policy between AP (ARUBA IAP 305) and HA port (allow any any) in the FW config. Broadcast and multicast are also allowed. (BLUE LINKS)

But if i connect the GW to the internet Router Wifi (Movistar MITRASTAR) and HA to the same router port it Works fine. It’s obvious the proble is in the FW or in the AP.
(ORANGE LINKS)

¿Could anyone tell me what prorocol uses HA to discover the GW inorder to enable/disable FW or AP features if posible?

Thanks in davance.

Sergio

In the documentation it says that you can specify the IP of the gateway manually, and thereby skip the discovery. That’s probably easier than resolving the issue. :smile:

Thanks!!

i tried that way but it didn’t work. What i did; Discover the GW in the second architecture, and work with first one. It works as a workarround but i’m still looking after the solution of discovering devices in the first one.

regards!!!

I have something similar.
Gateway is in a VLAN, HA server in another, both connected to the Forti.
Beside an UDP port 9898 from HA to the gateway, I have the multicast enabled from the gateway VLAN to the HA one…

You also have to enable the TTL transparency in the forti so that it doesn’t drop the message (most multicast/broadcast have TTL of 1 to remain in the same VLAN) :

config system settings
set multicast-ttl-notchange enable
end

This way it works for me, but I put the gateway IP address in the configuration.

Thanks a lot!

i Will try and post.

regards

Sergio