FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
rahul_p1
Staff
Staff
Article Id 419609
Description

This article shows HA is out of sync due to the error message: switch-controller.manage-switch.

Scope FortiGate, FortiSwitch.
Solution

This image shows that there is a configuration mismatch under switch-controller.manage-switch.

 

GUI.png

 

Check the checksum on the primary and secondary for the configuration of the switch controller.

 

Using the below command:

 

config switch-controller managed-switch

show full-configuration

 

Compare the differences in both configurations using a 'diff checker tool'.

 

If differences are shown for Dynamic-capability under switch configuration, then try to re-import the configuration on the secondary device from the primary device.

 

rahul_p1_1-1763540930570.png


Dynamic-capability option shows what features the switch supports and its non-configurable value.

The value differs for the switch model; it is not possible to change the value. 
Refer to the article: Technical Tip: 'dynamic-capability' flag on Managed FortiSwitch 

 

If the issue is still not resolved, contact Fortinet Technical Support.

 

Note :

  • To address the synchronization issue, carefully examine the dynamic-capability parameter for any discrepancies, as differences in this parameter could be the root cause.
  • Ensure that both systems or components involved have matching values for dynamic-capability, and if inconsistencies are found, update or align them accordingly to restore proper synchronization.

 

config switch-controller managed-switch
    edit "S248F"
        set name "SW2"
        set fsw-wan1-peer "fortilink"
        set fsw-wan1-admin enable
        set poe-detection-type 2
        set version 1
        set max-allowed-trunk-members 8
        set dynamic-capability 0x0000000000000000000027757dddbff7

 

Related article:

Troubleshooting Tip: How to troubleshoot HA synchronization issue using GUI and CLI on FortiGate/For...