Description |
This article discusses the problem when the session is not visible to other FGSP members:
On FGTA, the state of the session showed 'synced':
FGTA # diagnose sys session filter dst 23.50.89.168
FGTB # diagnose sys session filter dst 23.50.89.168
FGTA outgoing interface settings : edit "VLAN-800"
FGTB outgoing interface settings : edit "VLAN-1800" |
Scope | FortiGate v6.4 and v7.0. |
Solution |
Set the FGTB interface name to be the same as FGTA:
edit "VLAN-800"
The names of the VDOMs and any VLANs and LAGs or other interfaces added must be the same on both clusters, even though network addresses will be different.
Interface indexes (not the SNMP indexes) must be the same too, otherwise, sessions will not be synchronized properly. Interface indexes can be checked by the command:
diagnose netlink interface list |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.