FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Steff_FTNT
Staff
Staff
Article Id 315439
Description This article describes some technical considerations when FortiGate devices in an HA Cluster, Active-Passive mode, after a failover continue to load the secondary unit which previously was the primary.
Scope FortiGate, H-A.
Solution

This is the description of the reason for this unexpected behavior that is not an issue.

The following network diagram is used to illustrate this article :

 

 Steff_FTNT_0-1715853348129.png

 

 

The reason is linked to the firewall policy in proxy mode. The unit that starts the analysis needs to collect the entire file transported over the HTTPS session before giving a security verdict.

 

For this reason, the unit needs to analyze the file till the end of the session, even after a failover. Once the session is finished its traffic is not processed anymore by the secondary unit. All the sessions started after the failover will be processed by the new primary unit. After a certain time, the secondary unit stops being loaded.

 

 Steff_FTNT_1-1715853348139.png

 

 

Session on both units:

 

  Primary Secondary
sync

syn_ses

synced

speed(Bps/kbps)

tx 1369/10 rx 101514/812

tx 493/3 rx 78584/628

offload

offload=8/8

offload=0/0

no_ofld_reason: 

 

redir-to-av

 

 

The primary and the secondary comparisons show the details of this behavior. The unit that created the session when it was primarily marked it as 'synced', and the unit which received the session after a HA sync action reported it as 'syn_ses'.

 

Both units report active traffic for the related flows. The actual primary forwards the packets without analyzing them and for this reason, it can offload the traffic. The secondary receives the packets and needs to send them to the antivirus profile, which is the reason why it cannot offload the traffic.