Connectivity issue between Secondary FortiGate and FortiAnalyzer in HA cluster
I am experiencing a connectivity issue where the Secondary unit of a FortiGate HA cluster cannot connect to the FortiAnalyzer (FAZ).
Environment:
Device: FortiGate HA Cluster (Active-Passive)
Log Storage: FortiAnalyzer (FAZ)
Symptoms:
The Primary FortiGate connects to the FAZ normally.
The Secondary FortiGate shows a status error: "Could not connect to the FortiAnalyzer to retrieve its serial number."
On the FAZ side, both devices appear in the device list, but the Secondary unit is not sending logs correctly.
Troubleshooting Performed:
Certificate: Disabled "Verify FortiAnalyzer certificate", but the issue persists.
HA-Direct: The ha-direct setting is currently disabled.
Packet Capture: Ran diag sniffer packet any "host [FAZ_IP]" 4 0 l on the Secondary unit. Results: No packets were captured at all when attempting to connect to the FAZ.
The Secondary unit seems unable to initiate any traffic toward the FAZ IP.
