Description | This article explains the message about FortiGate HA enrolled in FortiCloud where the slave unit shows its management tunnel status as down. |
Scope | FortiGate and FortiCloud. |
Solution |
Problem:
This is an expected behavior. Since the slave unit is sharing the same physical IP address with the master unit, it is expected that only the online unit of the HA pair could connect to the manager server. Hence, only the active one can establish a tunnel with FortiGate Cloud.
Related documents: https://docs.fortinet.com/document/fortigate-cloud/22.3.0/administration-guide/480651/deployment
'For FortiGates that are part of high availability (HA) pair, it is necessary to activate FortiGate Cloud on the primary FortiGate. Activate FortiGate Cloud on the primary FortiGate to deploy a FortiGate/FortiWifi to FortiGate Cloud in the FortiOS GUI: describes.
FortiGate Cloud activation on the primary FortiGate activates FortiGate Cloud on the secondary FortiGate. Local FortiGate Cloud activation on the secondary FortiGate will fail.' |