Skip to main content
kdawd
Staff
Staff
February 25, 2025

Technical Tip: How to monitor HA cluster members individually through Public Interface using SNMPv3

  • February 25, 2025
  • 0 replies
  • 3046 views
Description

 

This article describes how to individually monitor HA cluster members, which are only accessible to the SNMP server through the external interface. In this scenario, ha-direct cannot be used on the cluster members.

 

Scope

 

FortiGate.

 

Solution

 

Starting from v7.6.0, snmpd supports querying the Secondary cluster member from the Primary FortiGate by adding the Secondary member's Serial Number after the username in the snmpwalk command, as shown below:

 

snmpwalk -v3 -l noAuthNoPriv -u username-FortiGate_Serial_Number Host_IP OID


Note:
For snmpv3 it is required that the Primary and Secondary cluster members have the same engine-id configured within config.system.snmp.sysinfo. See the below KB article for reference: Technical Tip: SNMP V3 trap configuration with FortiGate running HA

Related articles:
Technical Tip: SNMP communication working scenario with respect to FortiGate device in HA and ha-direct options
Technical Tip: OIDs for monitoring HA
Technical Tip: Setup FortiGate HA failover alert on SNMP managers (OID)

    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!