Skip to main content
Konnan
Explorer II
July 31, 2024
Solved

Configuration changes with override enabled - FGCP HA

  • July 31, 2024
  • 6 replies
  • 3436 views

Hello!

 

I'm setting up override on my cluster and I saw this article: Primary unit selection with override enabled | FortiGate / FortiOS 6.0.0 | Fortinet Document Library

 

It says that we lose configuration changes if the primary goes down, we do changes on secondary (that is going to be temporarily primary), primary comes back up, negociates to get his primary status back and overwrite the changes made on the secondary (who lost his temporary primary status).

 

By using the setting that the end of the article: set override-wait-time

Can we avoid losing configuration changes if the override-wait-time is long enough?

Does the secondary will have time to overwrite the primary configuration before primary negociates to get his status back?

 

I know that setting is there to smoothen the transition, but was wondering if it could have that nice side effect.

 

Thanks!

Konnan

Best answer by Toshi_Esumi

Direct answer would be no, there is no easy solution like flipping a setting to avoid configuration loss (or configuration override [not HA override]) when those situations happen.

The key is if the HA connection between the member units are up or down when the lower priority unit is the primary. As long as it's up config sync happens, like when the highest priority unit's monitored interface went down.

In case the highest priority unit dies, of course the config sync can't happen. But that case, you most likely get a new/RMA unit and bring it up as a "secondary", not the primary. Only after the config has synced you would set the priority higher.

In other words, when you bring up the faulted primary unit and put it back in the cluster, you need to be aware of the config status on all member units and control when/which unit becomes the primary and avoid taking over traffic by shutting down those in/out interfaces on the switch side.

This is not only when you set "override" but also in the non-override HA setting.

Toshi

6 replies

Shashwati
Staff
Staff
July 31, 2024

Hello

This override-wait-timer option configured under HA setting, it makes the former master unit wait for number of second before taking back the master role, this is to ensure that all the sessions and routing tables have been completely synced. Please refer to the document

https://community.fortinet.com/t5/FortiGate/Technical-Tip-HA-override-wait-timer/ta-p/196568

 

Konnan
KonnanAuthor
Explorer II
July 31, 2024

Hello Shashwati,

 

Maybe I wasn't clear enough, I know that part, that's not what I'm looking after. I know the main usage, it's to sync the sessions and routing tables.

 

I wonder if it would have a side effect of allowing the temporary master to sync the latest configuration changes with the former master, before it negociates to get his master status again.

 

Let say you put a timer of 15 minutes, that should be plenty to sync any policy change done on the temporary master to the former master? But then again, maybe it would not work in that case.

 

Thanks!

Konnan

Toshi_Esumi
SuperUser
SuperUser
July 31, 2024

Direct answer would be no, there is no easy solution like flipping a setting to avoid configuration loss (or configuration override [not HA override]) when those situations happen.

The key is if the HA connection between the member units are up or down when the lower priority unit is the primary. As long as it's up config sync happens, like when the highest priority unit's monitored interface went down.

In case the highest priority unit dies, of course the config sync can't happen. But that case, you most likely get a new/RMA unit and bring it up as a "secondary", not the primary. Only after the config has synced you would set the priority higher.

In other words, when you bring up the faulted primary unit and put it back in the cluster, you need to be aware of the config status on all member units and control when/which unit becomes the primary and avoid taking over traffic by shutting down those in/out interfaces on the switch side.

This is not only when you set "override" but also in the non-override HA setting.

Toshi

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.