Description | This article explains that the firewalls are out of sync status due to differences in the interface configuration settings speed as auto and how it should be resolved. |
Scope | FortiGate. |
Solution |
The firewalls are out of sync due to mismatched checksum of interface objects.
diagnose sys ha checksum show global <----- Checksums are different.
The configuration of interfaces is different due to the default setting speed auto.
show sys int port1<----- In the show command it is possible to see the 'set speed' command. Next
The '-->ERROR auto' is default and should not be displayed in the show command. However, on the other unit, this speed will not be displayed.
Interface setting on the second device:
show sys int port1<----- In the show command the 'set speed' command will not be visible.
This difference in configuration will make the system worse. interface object is different which results in a sync issue.
The solution for this issue is as follows:
diag sys ha checksum recalculate
After recalculating the checksum, the issue should be resolved and both devices will be in synchronization again.
If the issue is still not resolved, verify the configuration of other objects whose checksum is different. Refer to the below article to compare the checksum. Technical Tip: Troubleshooting a checksum mismatch in a FortiGate HA cluster |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.