Skip to main content
FortiKoala
Staff
Staff
September 28, 2018

Technical Tip: Reboot control and application servers configured for High Availability

  • September 28, 2018
  • 0 replies
  • 3800 views

Description

 

This article describes a procedure to reboot appliances in a Control Server/Application Server pair configured for High Availability (HA) without triggering a failover.

 

Note the following:

  • The steps outlined are for accessing appliances via CLI. If CLI access is not available, contact support for assistance. 

  • To reboot using the Administration UI, refer to the Power management section of the Administration Guide in this document: FortiNAC.

  • During this process, all management functionality is stopped:

    • VLAN switching.

    • Captive Portal pages.

    • RADIUS processing.

    • Registration of endpoints.

Scope

 

FortiNAC.


Solution

 

Important: If using an L2 HA configuration, do not access the CLI using the Virtual IP (VIP). The VIP becomes inaccessible once the control process is stopped.


Gracefully shut down processes on all servers.

 

  1. Shut down the control process in Primary Servers. In the Primary Control Server CLI, type:

shutdownNAC


  1. Wait 30 seconds. This shuts down control processes for both Primary Control and Application Servers.

  2. To verify that Control Process 'Yams' is no longer running, run the following command in the Control Server and Application Server CLI:

jps


  1. Shut down the management process. In each server CLI, type:

shutdownNAC -kill


Reboot appliances.

  1. In Primary Application Server CLI, type:

reboot


  1. Wait 30 seconds.

  2. In Primary Control Server CLI, type:

reboot


  1. Wait until the Primary Control and Application Servers are up and running (by confirming SSH access and Administration UI access). The startup could take anywhere between roughly 5–10 minutes. Suggest waiting that long before attempting to access the UI.

  2. In the Secondary Application Server CLI, type:

reboot


  1. In the Secondary Control Server CLI, type:

reboot


  1. After 4-5 minutes, confirm that the Administration UI dashboard shows all servers up. The Primary Server(s) should be in control and display the following status:

  • Primary Servers: Running - In Control.

  • Secondary Servers: Running - Not In Control.


On FortiNAC-F, the above commands need to be executed in the shell using the following command:

execute enter-shell
$shutdownNAC
$shutdownNAC -kill
$reboot

 

Related article:

Technical Tip: How to Power Down appliances in High Availability configuration
Guide: CLI reference manual 

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.