Skip to main content
stefano_gobbi
New Member
December 17, 2010
Question

Heartbeat device(interface) down

  • December 17, 2010
  • 11 replies
  • 10469 views
hello to evrybody. I have a cluster made of 2 fortigate. sometimes I get from logs this error from both appliance: Heartbeat device (interface) down - neighbor info lost I changed the cables that connect the appliances. But I get the same errors. Does anyone know what are the reasons of this errors? maybe one port of the appliance has problem? how could I get more information? I also checked the interface messages but there are no errors. thanks.

    11 replies

    ede_pfau
    SuperUser
    SuperUser
    December 17, 2010
    You have probably configured more than one heartbeat interface. Otherwise you' d have noticed (losing the HA interface means breaking up the cluster).
    stefano_gobbi
    New Member
    December 17, 2010
    yes, I have configured two heartbeat interface. But I don' t understand why. what could be the reasons the interfaces go down ? I' ve changed the cables. there are no errors in the interface info. do you have any advice?
    ede_pfau
    SuperUser
    SuperUser
    December 17, 2010
    As long as one of the two HA interfaces work...could it be heavy traffic on the interface so that heartbeat packets are lost?
    stefano_gobbi
    New Member
    December 17, 2010
    well...actually both HA interface go down...and I don' t suppose that the cause is heavy traffic of the interfaces because it happens also during the night when the appliance is doing nothing. The interfaces go down for some seconds and then go up. I don' t know what to check more..any idea? thanks
    ede_pfau
    SuperUser
    SuperUser
    December 17, 2010
    a) open a ticket with Fortinet support b) downgrade to a different patch level You didn' t mention: - do you have direct cabling between the FGs? - which FortiOS version?
    stefano_gobbi
    New Member
    December 21, 2010
    -yes, I have direct cabling between FGs. -v4.0,build0205,100629 (MR1 Patch 6) thanks.
    ede_pfau
    SuperUser
    SuperUser
    December 21, 2010
    Two more ideas: - 4.1.6 seems odd to me; I' ve had trouble with it in conjunction with IPSec. Try 4.1.4 and/or 4.1.8 instead. It' ll only cost you a couple of seconds without traffic. - about the cables: do you use cross-over TP? it might work with straight-through cables as well if the interface is GbE but that (auto-MDI/MDIX) could be a point of failure.
    stefano_gobbi
    New Member
    December 21, 2010
    yes I use cross-over. the interface is 100 Mbps/full duplex. do you think that updating the version cuold be a solution?
    ede_pfau
    SuperUser
    SuperUser
    December 21, 2010
    *read my lips* yes. At least you will eliminate one variable. Other than that I' m out of clues. If it is a hardware issue, you' ll have to replace the unit(s) to prove it. Changing the firmware is done quicker. But still, consider a support call in order to get a hardware replacement.
    stefano_gobbi
    New Member
    December 21, 2010
    thanks for support. I' ll follow your advice and I' ll update the discussion when I resolve the problem.
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!