Skip to main content
New Member
May 15, 2026
Question

Forti SIEM Collector and Supervisor Communication Issue

  • May 15, 2026
  • 1 reply
  • 72 views

Environment:

  • Cluster (Supervisor & Workers): Residing in VDC-A using private IPs. A Public IP pool is assigned to the VDC with NAT and Firewall rules mapping to the Supervisor and Workers.

  • Collector: Residing in VDC-B. It has a Public IP associated via NAT and is intended to communicate with the cluster over the internet.

  • Connectivity Status: Initial connectivity (Telnet/Curl) is verified and functional between the Collector and the Supervisor's Public IP.

The Problem: Although the Collector was provisioned successfully, it failed to appear in the Supervisor's Collector Health tab. Investigation of the logs revealed that during the registration handshake, the Supervisor provided its internal private IP (and the workers' private IPs) to the Collector. Consequently, the Collector attempted to establish a heartbeat using the unreachable private IP.

Current Progress & Obstacles:

  1. Partial Fix: I manually updated /opt/phoenix/config/phoenix_super.txt on the Collector, replacing the private IP with the Supervisor’s Public IP.

  2. Result: The Collector successfully reached the Supervisor, and its details now appear in the Health tab.

  3. Remaining Issue: The Collector still cannot communicate with the Worker nodes. Because it is still attempting to reach them via their private IPs, services such as phDiscover and phPerfMonitor remain in a Down state. As a result, the Supervisor is not receiving any files or performance data from this Collector.

Constraint: While an IPsec tunnel between the two VDCs is a possibility, the requirement is to achieve full functionality using the assigned Public IPs via NAT.

1 reply

Secusaurus
Contributor III
May 18, 2026

Hi ​@anju_125,

 

Most common issue for that is the missing or wrong configuration at Admin → Settings → Cluster Config.

After the initial handshake for provisioning, the Collector will only use the IPs/FQDNs provided there. If this is an edge case, you may provide distinct Worker-IPs/FQDNs for a Collector in the Collector setup, but a loadbalancer in front of the cluster would usually be the better place to configure that.

Best practice would be to use FQDNs in the cluster config and have an internal DNS resolution at the VDCs while using the public DNS resolution/address for everyone else.

 

Best,

Christian

NSE8 | Fortinet Advanced MSSP Partner
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!