Athena NGFW (Next-Generation Firewall)

Athena NGFW (previously known as Network Secure) provides comprehensive protection for every network perimeter, ensuring the safety of your valuable assets, data, and users from emerging threats.
{{ $t('productDocDetail.guideClickSwitch') }}
{{ $t('productDocDetail.know') }}
{{ $t('productDocDetail.dontRemind') }}
8.0.95
{{sendMatomoQuery("Athena NGFW (Next-Generation Firewall)","Fortigate Parameter Explanation and Conversion Suggestions")}}

Fortigate Parameter Explanation and Conversion Suggestions

{{ $t('productDocDetail.updateTime') }}: 2026-01-04

FortiGate Parameter

FortiGate Parameter Description

Corresponding Sangfor NGAF Module/Parameter

Migration Notes

mode

HA mode (a-p active-passive / a-a active-active)

System > High Availability > Settings

Directly corresponds

group-name

Cluster name

System > High Availability > Settings

Not applicable

group-id

HA cluster ID (to prevent conflict)

System > High Availability > Settings

Not applicable

password

HA cluster communication password

System > High Availability > Settings

Not applicable

hbdev

Heartbeat interfaces and priority

System > High Availability > Settings

NGAF supports multiple heartbeat interfaces

session-pickup

Session synchronization (TCP)

System > High Availability > Settings

Enabled by default

session-pickup-connectionless

Connectionless protocol synchronization (UDP)

System > High Availability > Settings

Not applicable

session-pickup-expectation

Auxiliary session synchronization (FTP, SIP, etc.)

System > High Availability > Settings

Recommended to enable

override

Force takeover policy

System > High Availability > Settings

Same mechanism in NGAF

priority

Node priority

System > High Availability > Settings

Higher value is primary

monitor

Link monitoring interfaces

System > High Availability > Settings

Can be used for failover determination

ha-mgmt-status

Enable dedicated management port

System > High Availability > Settings

Directly corresponds

ha-mgmt-interfaces

HA dedicated management interface configuration

System > High Availability > Settings

Recommended to use a dedicated port

unicast-hb

Unicast heartbeat (for multi-segment networks)

System > High Availability > Settings

Not applicable

ha-direct

Direct heartbeat synchronization channel

System > High Availability > Settings

Not applicable

sync-config

Configuration synchronization

System > High Availability > Settings

Enabled by default

encryption

HA communication encryption

System > High Availability > Settings

Enabled by default

ha-reserved-bandwidth

Reserved bandwidth for HA synchronization

System > High Availability > Settings

Not applicable