FortiAuthenticator
FortiAuthenticator provides centralized authentication services for the Fortinet Security Fabric including multi-factor authentication, single sign-on services, certificate management, and guest management.
jcastellanos
Staff
Staff
Article Id 277457
Description This article describes how to recalculate checksum in HA load balancer. Sometimes configurations seem to be similar (same LDAP user, groups, User profiles, User group membership, etc.).
Scope FortiAuthenticator v6.5.x.
Solution

Even if the number of users or groups could be similar, the FortiAuthenticator will be out of sync:

 

ha example error.PNG

screenshot1 (1).PNG


It is possible to check and recalculate the checksum and validate if the FortiAuthenticator get in sync.

 

Go the the Primary FortiAuthenticator:

There is a button that permits one to try repairing it (on the primary node, only) tucked away near the top right corner of https://FAC_IP/debug/lb_sync/ - mouse over them to find the right one.

 

kb-19 ha check sum.PNG

 

Verify if the device gets in sync.

 

3- ha after checksum recalculate.PNG