Description |
This article describes how, when configuring a High Availability (HA) cluster with FortiGate firewalls, a mode mismatch can occur if one device is set to Active-Active (A-A) and the other to Active-Passive (A-P). This misconfiguration results in warnings and prevents proper HA synchronization. HA mode mismatch error messages appear in debug logs: 2024-11-14 11:49:22 <hatalk:WARN> 'FG6H0FTB23901025 mode mismatch: hdr_mode=2, my_mode=1
The HA cluster must operate in the same mode across all participating FortiGate devices. A mismatch in HA mode settings leads to synchronization failures, preventing the cluster from functioning correctly. |
Scope | FortiGate. |
Solution |
Cause: The HA cluster must operate in the same mode across all participating FortiGate devices. A mismatch in HA mode settings leads to synchronization failures, preventing the cluster from functioning correctly.
get system ha status
config system ha set mode active-passive <- Or set mode active-active. end
execute reboot <- First on secondary.
diagnose sys ha status
Best practices to avoid HA mode mismatch:
By ensuring proper HA mode configuration, to maintain seamless failover and high availability of FortiGate deployment. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.