Skip to main content
luca1994
Explorer III
September 16, 2025
Solved

FGSP session monitor between FGCP clusters

  • September 16, 2025
  • 4 replies
  • 724 views

Hello Team,

 

I have two FortiGate 2600F FGCP clusters (active/standby) with FGSP enabled between them for a specific VDOM. 

I would like to verify whether FGSP sessions are synchronized and see which ones are.

 

The following CLI commands appear to report FGCP session information only:

diagnose sys session sync

diagnose sys session list 

 

How can I retrieve session information for FGSP specifically?

 

Thanks in advance for the support

Best Regards 

Best answer by AEK

Hi Luca

The document mentions the flag "syn_ses", not "synced".

If I remember well, synced is seen on the FG that first handled the session, while syn_ses is seen on the peer FGT that received the session info from the first FGT.

You can check from the GUI on FortiView sessions, use filter to select some sessions, you should see exactly the same sessions on both FortiGates, that means sessions are synchronized.

4 replies

AEK
SuperUser
SuperUser
September 16, 2025

Hi Luca

It is the same commands as you mentioned.

The sessions should have the session state "syn_ses", as described in this tech tip.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-FGSP-Configuration-Guide-for-Session-Sync-and/ta-p/197561

AEK
luca1994
luca1994Author
Explorer III
October 24, 2025

Hello @AEK ,

 

sorry for the delay.

When I run the command diagnose sys session list | grep synced I also seem to see FGCP sessions. Perhaps there are specific flags to look for in the session status, but the official documentation does not mention them.
I also tried contacting Fortinet TAC, but other than sharing the commands in the KB article you sent me, they were unable to answer my questions.

The FGSP protocol is not well documented.
I would like to be sure that the sessions are synchronizing and, more specifically, how to proceed in case of troubleshooting.

 

Thanks in advance for the support

BR

 

wukantu1
New Member
September 16, 2025

Is it typically the same speed as the main lan/wan links on the firewall or can it be less? In this scenario there won’t be a massive amount of asymmetric traffic due to the way the routing is being done.

AEK
SuperUser
AEKAnswer
SuperUser
October 26, 2025

Hi Luca

The document mentions the flag "syn_ses", not "synced".

If I remember well, synced is seen on the FG that first handled the session, while syn_ses is seen on the peer FGT that received the session info from the first FGT.

You can check from the GUI on FortiView sessions, use filter to select some sessions, you should see exactly the same sessions on both FortiGates, that means sessions are synchronized.

AEK
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.