Skip to main content
calink
Staff
Staff
November 13, 2025

Troubleshooting Tip: HA cluster will not sync due to wanopt mismatch

  • November 13, 2025
  • 0 replies
  • 1207 views
Description This article describes the steps to troubleshoot and resolve the issue of an HA not synchronizing due to a wanopt mismatch. 
Scope FortiGate.
Solution

Go to to System -> HA and hover over the Secondary to see what is out of sync.


The 'Not Synchronized' status will show the object 'wanopt.settings' checksum is not matching.

The specific checksum can be checked using the following method.

 

From CLI:

Run the command below on both units in the cluster and compare the checksum values:

 

diagnose sys ha checksum show root wanopt.global

 

If the checksum does not match, verify on each unit in the cluster if there are differences in the settings and ensure they match on both units. If they already are the same on both units, run the following commands to force a recalculation of the checksums.

 

To resolve the wanopt.settings mismatch, change the default 'default-id' in the WANOpt settings on the primary FortiGate by running the following commands:

 

config wanopt settings

    set host-id temp-id

end

 

Once the change has been made on the Primary FortiGate, recalculate the checksum with the following command:

 

diagnose sys ha checksum recalculate

 

At this point, the cluster should be in sync again.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!