Skip to main content
ehammett
New Member
July 28, 2011
Question

How to reboot active-passive cluster?

  • July 28, 2011
  • 8 replies
  • 66138 views
I currently have a Active-Passive cluster between to Fortigate 110C devices. If I reboot the Master does it transfer the operations to the slave device? I would like to just reboot the device without anything failing over. Is this possible?

    8 replies

    ede_pfau
    SuperUser
    SuperUser
    July 28, 2011
    Hi, I would think that - reboot via the GUI would reboot all cluster members - reboot via CLI, started from a local CLI, would reboot that machine only Frankly, I' ve never rebooted a cluster just for fun; only during firmware updates. You can access the member' s CLI via
     exe ha man <ID>  exe reboot
    where ID would be 0 or 1. When you first login via ssh, you' re on the master unit. You can get the IDs with ' diag sys ha status' . If you just reboot the master via ' exe rebo' then of course it will failover to the slave. If you reboot the slave noone will notice...
    ehammett
    ehammettAuthor
    New Member
    July 28, 2011
    Hi thanks for the reply. I am not just rebooting it for fun, the problem I am having is the master device is not showing the correct active Fortiguard services. For instance the Web Filtering is showing expired however it is good for another year (even according to the Fortinet support website). So for whatever reason it is not being updated or synchronizing with the Fortinet support website. When I have seen this in the past a simple reboot of the device usually fixed it however I was unsure what the consequence would be in this instance. Do you know of a way to force the Fortiguard services to be updated to their correct information?
    ede_pfau
    SuperUser
    SuperUser
    July 28, 2011
    I' ve seen that with other FGTs before. Sometimes activating ' push updates' did it; the FGT has to register with the next FortiGuard server to leave its WAN IP there, and at that occasion the services info was updated. You might give it a try. Usually the slave lags behind, even in signature updates. From the theory this shouldn' t happen. Promoting the slave fixes this for a while.
    Matthijs
    New Member
    July 28, 2011
    on the cli:
      execute update-now  
    ede_pfau
    SuperUser
    SuperUser
    July 29, 2011
    That will only force a signature update; the crucial point is that the unit should first register with the FDS server:
     config system autoupdate push-update      set status enable  end  
    An actual update is not necessary then.
    Matthijs
    New Member
    July 29, 2011
    I have solved the same problem just by trying a signature update via the CLI ;-) Although the command should do a signature update, it solves the registration problems some sometimes. Rebooting a unit via the GUI does activate the slave, and the slave does not reboot. So you could just reboot the master that way.
    laf
    New Member
    February 19, 2012
    What command did you used?
    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!