Skip to main content
preetisingh
Staff
Staff
May 22, 2026

Troubleshooting Tip: FIPS-CC mode enabled, secondary VM Checksum empty after serial number and HA Page fails to load in GUI

  • May 22, 2026
  • 0 replies
  • 267 views

Description

This article describes an issue where, with FIPS-CC mode enabled in FortiGate HA, the System -> HA page fails to load in the GUI on both primary and secondary devices.

Scope

FortiGate 7.6.

Solution

With FIPS-CC mode enabled on FortiGate HA, the System -> HA page fails to load in the GUI on both primary and secondary devices.

fe91b5a8.png


Spoke1-HA1 # get system  ha status  
HA Health Status: OK
Model: FortiGate-VM64-KVM
Mode: HA A-P
Group Name: fortinet
Group ID: 10
Debug: 0
Cluster Uptime: 0 days 0h:47m:32s
Cluster state change time: 2026-05-18 06:15:32
Primary selected using:
    <2026/05/18 06:15:32> vcluster-1: FGVMxxxxxxxxx049 is selected as the primary because its uptime is larger than peer member FGVMxxxxxxxxx556.
    <2026/05/18 05:30:30> vcluster-1: FGVMxxxxxxxxx049 is selected as the primary because it's the only member in the cluster.
ses_pickup: disable
override: disable
Configuration Status:
    FGVMxxxxxxxxx049(updated 3 seconds ago): in-sync
    FGVMxxxxxxxxx049 chksum dump: 11 5c b7 7c 24 35 a0 ee 4d 22 b5 70 c2 11 68 a8 
    FGVMxxxxxxxxx556(updated 1 seconds ago): out-of-sync
    FGVMxxxxxxxxx556 chksum dump: 48 3c 3d 0e b8 49 67 01 b5 50 ec a8 7c 6a 49 74


The HA checksum cluster on the primary unit shows checksum verification missing for the secondary unit, and vice-versa.

Spoke1-HA1 # diagnose  sys  ha  checksum cluster  
================== FGVMxxxxxxxxx049 ==================
is_manage_primary()=1, is_root_primary()=1
debugzone
global: 26 5e e1 6c 43 5c 1d 19 de d0 46 25 c2 2b fa f8 
root: 86 e7 80 c2 8e c6 b7 29 1b 93 34 b6 af 3e b7 30 
all: 11 5c b7 7c 24 35 a0 ee 4d 22 b5 70 c2 11 68 a8 
checksum
global: 26 5e e1 6c 43 5c 1d 19 de d0 46 25 c2 2b fa f8 
root :


This is due to a known issue reported under ID 1215724 where the IPsec tunnel (enabled automatically for FIPS-CC mode) protecting the HA links fails to establish when one firewall is in FIPS-CC mode. This is caused by the hardcoded DH groups (31 or 32) in the automatic configuration.

This issue is resolved in FortiOS version 8.0 and FortiOS 7.6.7.

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!