Created on
03-04-2024
12:52 AM
Edited on
07-07-2025
05:50 AM
By
Jean-Philippe_P
This article describes how to troubleshoot the FortiAnalyzer HA failover issue in the Google Cloud Platform (GCP).
FortiAnalyzer-VM for GCP.
FAZ # config system admin settings
(setting)# set shell-access enable
Enter new password:
Confirm new password:
(setting)# end
Note:
Ensure the shell password is not lost, as the password cannot be reset/recovered.
As of FortiManager/FortiAnalyzer version 7.6.0 onwards, shell access has been removed and cannot be achieved.
Shell access is not available starting from v7.2.6 onwards or v7.4.4 onwards.
FAZ # exe shell
Enter password:
bash$ vi /drive0/private/clusterd/faz-ha.log
bash$ tail -f /drive0/private/clusterd/faz-ha.log
FAZ # diagnose ha failover
Troubleshooting commands:
diagnose ha status
diagnose ha stats
diagnose test app cluster 1
diagnose test app cluster 3 conn
diagnose test app cluster 3 log
diagnose test app cluster 97 status
execute shell
cat /etc/keepalived/keepalived.cfg
cat /drive0/private/clusterd/faz-ha.log
cat /drive0/private/clusterd/keepalived.log
diagnose sniff packet portX "vrrp" 3
Related articles:
Technical Tip: How to configure FortiAnalyzer HA instance in Google Cloud Platform (GCP)
Technical Tip: FortiAnalyzer HA Configuration and Troubleshooting
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.