Troubleshooting Tip: FortiClient EMS not reachable from FortiGate secondary HA cluster unit
| Description | This article describes how to resolve an issue where the FortiGate secondary cluster cannot connect to the FortiEMS through the fabric connector. |
| Scope | FortiGate (active-passive HA), FortiClient EMS. |
| Solution | In a FortiGate active-passive cluster, the passive HA cluster unit generally does not connect. Once logged in through a passive device with the management interface, it will be visible that FortiClient EMS is unreachable. This is an expected behavior.
While checking the connectivity in the following ways, the output may appear as follows.
Primary:
Secondary: uranium-esx10 # diagnose endpoint fctems test-connectivity 1
uranium-esx10 # execute fctems verify 1 Command fail. Return code -9999
When the cluster is operating normally, only the Active unit is responsible for handling traffic and initiating outbound connections. This includes communication with FortiClient EMS. As a result, the Active FortiGate establishes and maintains the connection, and it is the only one that appears as 'connected' within FortiClient EMS. The Passive unit, on the other hand, remains in standby mode. Although it continuously synchronizes configuration and is fully prepared to take over at any moment, it does not independently communicate with FortiClient EMS or any external system while it is in this passive role. |

