Skip to main content
dbu
Staff
Staff
May 29, 2026

Technical Tip: Best Practices and Recommendations for FortiNAC Manager Cluster Management

  • May 29, 2026
  • 0 replies
  • 104 views

Description

This article describes best practices for FortiNAC Manager Cluster Management.

Scope

FortiNAC Manager.

Solution

FortiNAC Manager Cluster Management provides high availability and centralized management by allowing multiple Manager nodes to operate as a cluster. Following these recommendations can help maintain cluster stability, ensure successful synchronization, and simplify operational management.


Keep all Cluster Nodes on the same firmware version, patch level, or hot fix. Version inconsistencies may lead to synchronization issues or unexpected cluster behavior.

Monitor Cluster Health regularly. Go to System -> Cluster Management and verify:

  • One node is operating as the leader.

  • Worker nodes are online.

  • All nodes have the status 'Running'.


Verify database replication after each change. Do not assume that replication is functioning fine because all nodes report a Running status.


Validate cluster operation after upgrades. After each upgrade, confirm:

  • All Cluster members rejoined successfully.

  • Expected Leader node is Active.

  • Confirm Database Replication.

  • If replication fails, review cluster logs for synchronization errors.


Perform a failover test. Test periodically cluster failover by promoting a Worker node to Leder. Regular testing helps validate cluster stability before an unplanned outage occurs. Verify:

  • Cluster role updates correctly to Leader.

  • GUI access remains available.

  • Replication continues to function.

  • All nodes show a healthy state.


Create a backup before any cluster maintenance, such as upgrading software, adding/removing cluster members, performing major configuration changes, or modifying cluster roles.

Monitor synchronization logs to detect any replication failures, communication issues between cluster members, or any delayed synchronization event.


Use reliable network connectivity between cluster members. Cluster communication relies on stable communication between the Manager nodes.  If communication is unstable, it can affect replication and leader election operations. If possible, use:

  • Low-latency communication paths.

  • Reliable DNS resolution.

  • Consistent routing.

  • Minimal packet loss between nodes.


Worker order and Failover behavior. During a Leader failure, FortiNAC selects a new Leader from the available Worker nodes.  To better predict the failover behavior, do:

  • Review the Worker order after cluster deployment.

  • Place the preferred standby Manager at the top of the Worker list. Election is based on a top-down approach.

  • Ensure the Worker node has enough resources to take the Leader role.

  • Re-evaluate the Worker order whenever a new Manager is introduced to the cluster.


Related documentation:

Manager Cluster Guide

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.