Troubleshooting Tip: 'Out of sync' noticed in Load Balancer setup on FortiAuthenticator
Description
This article describes how to fix the 'Out of sync' error noticed in a Load Balancer setup.
HA status from the primary node:

HA status from the Load Balancer node:

Scope
FortiAuthenticator v6.6.x, v8.0.x.
Solution
Navigating to Dashboard -> HA status will show that certain tables between the primary and the Load Balancer cluster are not synced correctly, resulting in the common error 'Out of sync'.
Selecting 'Out of sync' will open a page to to show the exact parameters that are not synced correctly.
For instance:

Rebuild HA tables on the Load Balancer node.

Navigate to the debug page of the primary FortiAuthenticator at https://x.x.x.x/debug, where x.x.x.x is the appropriate IP address.
Navigate to High Availability -> Loadbalancing HA Sync, and select 'Recalculate LB-HA checksums' on the Load Balancing HA sync.


These errors are usually seen if checksums on both ends do not match. If the issue still persists, open a ticket with Fortinet Technical Assistance Center (TAC). See Customer Service Tip: How to create a ticket for Fortinet TAC.
Note: This will also work if other listed properties such as LDAP RADIUS attributes, server certificates, etc. also fail to be synced.
More details on what can be synced can be found in Technical Tip: How to configure FortiAuthenticator load-balancing cluster.
