Technical Tip: Logging behavior when FortiGate is configured in active-passive HA mode
| Description | This article describes how logging to external syslog servers behaves when FortiGate is deployed in an active-passive High Availability (HA) configuration. |
| Scope | FortiGate, external syslog server. |
| Solution | In an active-passive HA setup, only the primary (active) FortiGate is responsible for forwarding logs to external logging servers (for example, a syslog server or FortiAnalyzer). The secondary (passive) unit does not independently establish connectivity or routing to the syslog server. On the primary FortiGate, a valid route to the syslog server IP address is present: Primary: FG***********916, HA operating index = 0 get router info routing-table details 10.5.148.84 On the secondary FortiGate, no route to the syslog server IP is displayed: FG3H0E-4 # get router info routing-table details 10.5.148.84 This behavior is expected and does not indicate a configuration or routing issue on the secondary unit.
The following article can be referred to for configuring syslog on FortiGate: Technical Tip: How to configure syslog on FortiGate.
Example packet captures for the logs related to the primary and secondary units:
|


