This article explains the exact behavior during the HA upgrade in a Virtual Cluster environment with the HA override wait timer configured.
The following configuration example will be used for explanation:
FortiGate A:
config system ha
set group-id 10
set group-name "HA-Group"
set mode a-p
set password Password
set hbdev "ha" 100 "port9" 150
set session-pickup enable
set session-pickup-connectionless enable
set ha-mgmt-status enable
config ha-mgmt-interfaces
edit 1
set interface "mgmt"
set gateway 192.168.1.1
next
end
set vcluster-status enable
config vcluster
edit 1
set override enable
set priority 130
set override-wait-time 900
set monitor "port5"
set vdom "VDOM1"
next
edit 2
set override enable
set priority 250
set override-wait-time 900
set monitor "port5"
set vdom "VDOM2"
next
end
end
FortiGate B:
config system ha
set group-id 10
set group-name "HA-Group"
set mode a-p
set password Password
set hbdev "ha" 100 "port9" 150
set session-pickup enable
set session-pickup-connectionless enable
set ha-mgmt-status enable
config ha-mgmt-interfaces
edit 1
set interface "mgmt"
set gateway 192.168.1.2
next
end
set vcluster-status enable
config vcluster
edit 1
set override enable
set priority 250
set override-wait-time 900
set monitor "port5"
set vdom "VDOM1"
next
edit 2
set override enable
set priority 130
set override-wait-time 900
set monitor "port5"
set vdom "VDOM2"
next
end
end
FortiGate Virtual Cluster behavior during the upgrade, depending on the HA override wait timer setup.
Based on the configuration shown above, here is what happens exactly:
In addition, to let FortiGate A wait after the upgrade, set override-wait-time on one cluster.
For example:
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.