FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
ssriswadpong
Staff & Editor
Staff & Editor
Article Id 220932
Description This article describes the behavior when editing a default-qos-type in an HA environment.
Scope FortiGate NP7 models.
Solution

After editing the default-qos-type to shaping or policing, FortiGate will be rebooted.

 

FG1K1F-1 # config system npu

FG1K1F-1 (npu) # set default-qos-type shaping

FG1K1F-1 (npu) # end
The configuration will take effect after system reboot.
Do you want to continue? (y/n)y


If HA is enabled, HA members will be rebooted at the same time.

Untitled2.png

 

Untitled.png

 

If 'n' is selected, the change will be discarded, so it is not possible to make a change and then reboot later.

The option to minimize the impact and reduce the downtime is isolating the secondary unit by disconnecting all the cables (including the HA cables). 

 

Then proceed with the change on the secondary (via console cable). The secondary will reboot, meanwhile, the primary is still in production.

When the secondary is up again, it is time to move the traffic from the primary to the secondary.

Remove all the cables from the primary to isolate it. At this moment, downtime will happen.

Reconnect all the cables to the secondary unit. Proceed with the necessary tests to validate the operation of the environment.

 

If everything is working as expected, apply the NPU change to the primary unit.

When the primary is up, reconnect only the HA cables and wait for the sync.

Reconnect all the cables of the primary unit.


This behavior has been changed from version 7.4.2 onwards. The secondary will reboot first, followed by the primary reboot when changing the default qos-type to shaping or policing.

 

Picture1.png

 

Note:

Starting from v7.6.3, default-qos-type cannot be changed to shaping for sessions offloaded to NP7 processors.

 

config system npu
    set default-qos-type {policing | shaping}
end

 

Instead, default-qos-type can only be set to policing.