Skip to main content
RolandBaumgaertner72
New Member
September 19, 2024
Question

Lost connection to Slave after Update

  • September 19, 2024
  • 25 replies
  • 6553 views

Hello,

 

this morning we decided to update a FG80F cluster from 7.4.4 to 7.4.5.

 

Stupid from my side, I did not check if the HA was synced and I did not notice anything wrong. I uploaded 7.4.5 and I lost access to the FG so that the Slave did not enter in the game.

 

After restart of the master we still had no sign of the slave. Since this is a remote side I asked a person to remove all cables from the slave unit and try to connect via port 1 LAN but there is no ping. Than we restarted the slave thinking that it might start as master but still no access. This unit for sure did not update to 7.4.5 and being with another OS it will not work in the HA anymore.

 

Any ideas to solve this? At the end there is just the option to access via console? Only change to reset and start HA over?

 

Thanks!

25 replies

RolandBaumgaertner72
New Member
September 27, 2024

Hello Piyush,

 

what do you mean upload firmware, both FG80F are on 7.4.5. We had on the slave this known bug updating from 7.4.3 to 7.4.4 some months ago, at the end node 2 never got updated and we didnt see any failures in HA. Than after updating 7.4.5 when we dondt expect any failures not knowing that node 2 was not even on 7.4.4 we lost connection to node 2. I reseted node2 and updated to 7.4.5, than it was shown in the HA again but with this one table missing.

 

Why is the config different when both nodes are on 7.4.5? 

 

On Node 1:

config system custom-language
    edit "en"
    next
    edit "fr"
    next

On Node 2:

config system custom-language
    edit "en"
        set filename "en"
        set comments ''
    next
    edit "fr"
        set filename "fr"
        set comments ''

 

Makes no sende since Node2 was reseted and got the config from Node1.

 

Now I am not even sure that failover is working and since this cluster is far away I am not risking booting the Node1.

 

Any other workaround?

 

Thanks  

AEK
SuperUser
SuperUser
September 27, 2024

Hi Roland

If this is the only difference between the two node configs (config system custom-language), can you just make them similar? i.e.: copy this portion from one node to the other.

On the other hand, on menu System > HA, when you hover the secondary node you should see which config sections are not synced. Can you share the screenshot?

AEK
RolandBaumgaertner72
New Member
September 27, 2024

Hi,

 

but how do I get the log, I dont want to restart not knowing the failover works fine...also not now in Business Hours.

 

HA_Failure.pngThanks,

Roland

AEK
SuperUser
SuperUser
September 27, 2024

Hi Roland

Thanks for the screenshot. It shows there is only one non-important section that is not synced. This should not be hard to fix.

You don't need to restart the primary. Just enter the command "get system startup-error-log" and share the output. It will show if there is an anomaly in this section due to some upgrade you may have done before.

AEK
RolandBaumgaertner72
New Member
September 30, 2024

Hi,

 

we found some suggestions on Reddit and in some cases it got solved with a reboot of the master unit. So we did that and the Slave took over without any problems. So the HA failure is working. After the Master rebooted we waited like 10mins but there is still the NO SYNC of the custom language line. We also did on both units diagnose sys ha checksum recalculate but it is still the same.

 

I never did changes on the config on an active unit so I dont know if it risky or not?

 

No other option? Stupid bug, no? I mean both units were updated to 7.4.5, why is this field different?

 

Thanks

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!