This article describes how to configure FortiGate HA Reserved Management Interface.
It provides direct management access to each individual cluster unit by reserving a management interface as part of the HA configuration.
A different IP address and administrative access settings can be configured for this interface for each cluster unit.
This simplifies the use of external services such as SNMP to monitor and manage the cluster units.
It is not possible to use this interface to route traffic as it is an Out-Of-Band management interface for each individual cluster member, use a different subnet for 'HA Reserved Management Interface (Out-Of-Band) than the cluster access subnet, and if the need is to use the same subnet than consider to use In-Band Managemen as explained in this article:
The Port wanted to use for 'HA Reserved Management Interface' should not be referenced/used in any configuration.
The interface needs to be cleared from all configurations and references, and 'Ref' needs to be 0.
For FortiOS 6.4.x and newer versions.
Configuration using CLI:
config system ha
set ha-mgmt-status [enable|disable]
set interface <interface name>
set gateway <xxx.xxx.xxx.xxx>
As an example, this is how this configuration looks on CLI: