FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
lestopace
Staff
Staff
Description This article explains the message about FortiGate HA enrolled in FortiCloud where the slave unit shows its management tunnel status as down.
Scope FortiGate and FortiCloud.
Solution

Problem:

 

lestopace_0-1663049298655.png

 

This is an expected behavior.

Since the slave unit is sharing the same physical IP address with the master unit, it is expected that only the online unit of the HA pair could connect to the manager server.

Hence, only the active one can establish a tunnel with FortiGate Cloud.

 

Related documents:

https://docs.fortinet.com/document/fortigate-cloud/22.3.0/administration-guide/480651/deployment

https://docs.fortinet.com/document/fortigate-cloud/22.3.0/administration-guide/868022/frequently-ask...

 

'For FortiGates that are part of high availability (HA) pair, it is necessary to activate FortiGate Cloud on the primary FortiGate.

Activate FortiGate Cloud on the primary FortiGate to deploy a FortiGate/FortiWifi to FortiGate Cloud in the FortiOS GUI: describes.

 

FortiGate Cloud activation on the primary FortiGate activates FortiGate Cloud on the secondary FortiGate. Local FortiGate Cloud activation on the secondary FortiGate will fail.'

 

Contributors