Description |
This article describes the criteria for selecting the primary unit in a FortiGate High Availability (HA) cluster, depending on whether the override feature is enabled or disabled. The criteria include the number of operationally UP Monitored interfaces, HA uptime, priority, and serial number of the devices. |
Scope | FortiGate. |
Solution |
Confirm whether the override is enabled using the following commands:
show system ha
Primary unit selection criteria when override is disabled (MUPS):
Additional note: If the HA uptime difference between the two units is less than ha-uptime-diff-margin (default value is 300 seconds), then Priority will be considered as per the 4th point above. This would usually happen during HA cluster firmware upgrade if an upgrade between clusters happens in less than ha-uptime-diff-margin, then Primary will be selected based on the highest Priority.
To check the HA cluster members' uptime:
get system ha status
Related article: Technical Tip: How to verify HA cluster members individual uptime
Some points to remember about primary unit selection:
Primary unit selection criteria when override is enabled (MPUS):
If the Primary unit has lower priority and if the override is enabled, even only on the primary and not on the secondary unit, this will still trigger HA Failover. Ensure the priorities are set as intended to avoid accidental HA Failover.
Related documents: Primary unit selection with override disabled (default) Primary unit selection with override enabled Technical Tip: HA age time difference (HA cluster uptime) Technical Tip: How to verify HA cluster members individual uptime |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.