Description | This article describes an expected behavior for FortiGates on a cloud platform, that HA becomes out of sync when an IP address is configured on an IPsec interface. |
Scope | FortiGate-VM v7.4 and v7.6 in Cloud environments |
Solution |
This article describes an issue seen in HA deployment on the cloud. HA goes out of sync when an IP address is configured on an IPsec interface.
config system interface edit "IPsec interface" set vdom "root" set ip 10.255.255.1 255.255.255.255 set type tunnel set remote-ip 10.255.255.254 255.255.255.0 next end
Below are the platforms that do not sync the interface's IP:
The issue can be verified by running the following debug on the secondary unit:
diagnose debug reset
The line -118: end indicates an error while committing the changes.
The workaround is to manually configure the IP fields ('set ip' and 'set remote-ip') on the secondary unit.
A fix to allow synchronizing the 'remote-ip' without checking for a value in the 'set ip' parameter is planned for v8.0.0. Note that even when this fix is applied, the tunnel local IP address will not be synced between HA FortiGates on a Cloud platform. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.