Skip to main content
zinkt-101
Explorer
March 7, 2025
Question

HA Reserved Mgmt Interface for FortiGuards, Syslog, SNMP, etc

  • March 7, 2025
  • 6 replies
  • 2004 views

New Firewalls HA Setup with Reserved Management Interface

- I have a FortiGate400F internal firewall(not directly connected to internet) with HA A/P mode and three VDOMs.(root, vdomA and vdomB)

- I use my OOB mgmt interface as reserved mgmt in order to monitor both the primary and secondary firewall

FW1 mgmt IP : 192.168.1.1/24 (port 'mgmt)

FW2 mgmt IP : 192.168.1.2/24 (port 'mgmt)

- I also want OOB mgmt interface to use for other services such as SNMP, Syslog.

- Therefore, I have config 'ha-direct enable' so that the Syslog and SNMP traffic is passing through via that OOB mgmt interface.

- However, after reserved interface config, FortiGate is unable to reach to FortiGuards services due to no routing via reserved mgmt interface.

- i want the mgmt interface handle all the things (mgmt, FortiGuards, License, SNMP, Syslog, RADIUS, etc)

 

How can I archive this setup or what will be the best approach to meet my requirements.

thank you.

6 replies

abarushka
Staff
Staff
March 7, 2025

Hello,

 

Could you please clarify whether routing is configured for HA management?

 

Routing table (management) can be verified by running the commands below:

 

execute enter vsys_hamgmt

get router info routing-table all

zinkt-101
zinkt-101Author
Explorer
March 7, 2025

Hi @abarushka 

Routing is not configured for HA mgmt as we cannot add routing via HA reserved mgmt interface.

Before I config my mgmt interface as

HA reserved mgmt, i have default route configured via mgmt inf to route traffic for all services like snmp, syslog, FortiGuard, license and system dns, etc .

abarushka
Staff
Staff
March 7, 2025

Hello,

 

Is there any particular reason why HA management interface routing is not configured? You can find a sample configuration below:

 

config system ha
config ha-mgmt-interfaces
edit 1
set interface <interface>
set dst <destination IP>
set gateway <IPv4 gateway>
next
end
end

 

https://docs.fortinet.com/document/fortigate/7.4.0/administration-guide/313152/out-of-band-management-with-reserved-management-interfaces

 

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!