FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
qyah
Staff
Staff
Article Id 351699
Description This article describes how a firewall policy hit count will only update on the first FortiGate for the FGSP Cluster
Scope FortiGate, FortiOS v7.4.X
Solution
  1. For the example below, the first FortiGate is the first device of the joined FGSP cluster and the second FortiGate is the second device that joined the cluster, the configuration for the FGSP cluster can be completed by referring to the administration guide.

 

qyah_0-1729653779522.png

 

qyah_1-1729653779523.png

 

  1. From the First FortiGate, observe that the policy hit count increased when the session has been synced among the FortiGate:

The following shows the hit count increased on the first FortiGate:

 

qyah_2-1729653779525.png

 

The following shows that the hit count does not update on the second FortiGate:

 

qyah_3-1729653779527.png

 

  1. The session table shows that the session is being synced on the first FortiGate to the second FortiGate:

FGSP_First.png

 

  1. From the session table below observes that the session is being synced to the second FortiGate from the first FortiGate:

FGSP_Second.png

 

  1. This knowledge base article below can be referred to for the configuration on FGSP for session synchronization and configuration synchronization.
Contributors