Description | This article describes how to fix HA out of sync which can be caused due to the command 'set password-expire' mismatching and admin credentials do not work on the Secondary unit. |
Scope | FortiGate. |
Solution |
When going to FortiGate -> System -> HA the HA is out of sync due to the system.admin table:
In such a case, proceed to check the system admin section config by running the command: 'show system admin'.
FGVM02TM22026828-VBA~IOS # show system admin
Due to there being no access to the SECONDARY unit, it was not possible to confirm what are the dates/times set with the 'password-expire' command on the peer unit which might be mismatching so it was not possible to adjust it manually.
To fix the authentication and HA out-of-sync issues, apply the following:
FGVM02TM22026828-VBA~IOS # config system admin FGVM02TM22026828-VBA~IOS (admin) # edit admin FGVM02TM22026828-VBA~IOS (admin) # unset password-expire FGVM02TM22026828-VBA~IOS (admin) # end
FGVM02TM22026828-VBA~IOS # diagnose sys ha checksum recalculate
FGVM02TM22026828-VBA~IOS # diagnose debug app hasync 25
Proceed to check with the command 'get system ha status' until both devices show back to in-sync state. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.