Skip to main content
magnumpi
New Member
September 3, 2015
Question

fortigate active active problem

  • September 3, 2015
  • 4 replies
  • 5072 views

Hi, I have two fortigate 200B (5.0.11) in active-active mode, but from today there is only a small balance of tcp sessions. master has 1571 in ESTABLISHED state , but subordinate has  3 in ESTABLISHED state.

 

 

could someone help me

thanks a lot

    4 replies

    emnoc
    New Member
    September 3, 2015

    Qs:

     

    Q1: was this working before or did this just now stop

     

    Q2: if yes,  is the  2nd unit all healthy

     

    Q3: what does your load-balance under "config system ha" show ALL UDP etc.....

     

    Q4: was any changes made in the HA configuration of the configuration

    magnumpi
    magnumpiAuthor
    New Member
    September 3, 2015

    q1-> yes before q2-> I can connect to it by ssh without problem or webpage and I do not see problem q3-> fortigate1 (ha) # get group-id            : 0 group-name          : FGT mode                : a-a password            : * hbdev               : "port9" 50 "port10" 50 session-sync-dev    : route-ttl           : 10 route-wait          : 0 route-hold          : 10 sync-config         : enable encryption          : disable authentication      : disable hb-interval         : 2 hb-lost-threshold   : 6 helo-holddown       : 20 gratuitous-arps     : enable arps                : 5 arps-interval       : 8 session-pickup      : disable update-all-session-timer: disable session-sync-daemon-number: 1 link-failed-signal  : disable uninterruptible-upgrade: enable ha-mgmt-status      : enable ha-mgmt-interface   : port14 ha-mgmt-interface-gateway: 10.131.124.1 ha-eth-type         : 8890 hc-eth-type         : 8891 l2ep-eth-type       : 8893 ha-uptime-diff-margin: 300 vcluster2           : disable vcluster-id         : 1 override            : disable priority            : 200 schedule            : round-robin monitor             : "port13" "port15" pingserver-monitor-interface: pingserver-failover-threshold: 0 pingserver-flip-timeout: 60 vdom                : "root" load-balance-all    : disable q4-> no changes

     

    thanks

    emnoc
    New Member
    September 3, 2015

    load-balance-all    : disable

     

    Can you adjust this? Was it ever adjusted? ( look at your  config system ha options from the cli ( load-balance ) )

     

    edit: please becarefull if you load-balance all or make adjustments. I would do this on a load peak hour and monitor for the next 1-4 days for any issues. Sometime A-A doesn't work very good imho and experience.

     

    magnumpi
    magnumpiAuthor
    New Member
    September 3, 2015

    I have just reboot subordinate fortigate and now the balance is better.

    master Active Sessions= 8355   and subordinate= 1123

     

     

    thanks