Fortigate HA out of sync
This is the second time I have come across a Fortigate HA pair that would not sync back up when recalculating the checksums.
The first time was with a pair of 60f units, the standby unit had a Fortilink interface name that started with a capital letter while the primary unit had it in lower case. This was a brand new setup so we broke the HA pair, formatted the standby and redid HA.
This time around, it's a pair of 1500d firewalls in our datacenter. I narrowed the issue down to a missing address group on the standby. This group on the primary is the second to last. If I manually add this missing addrgrp to the standby, the order won't match the primary and the uuid would be different.
What's the solution, unreference this group from the policies on the primary, delete the group, then re-add it?
Denny
