Related article:
Created on
12-09-2025
09:52 PM
Edited on
12-18-2025
05:29 AM
By
Jean-Philippe_P
| Description | This article describes how to fix a high availability out-of-sync issue, which can be caused by a configuration mismatch in the FortiGuard settings. |
| Scope | FortiGate. |
| Solution |
show system fortiguard
To access the secondary unit, use the commands:
execute ha manage [ID][username] <----- Where ID can be 0 or 1.
For more detailed information about accessing the secondary appliance, check this KB article: Technical Tip: How to access secondary unit of HA cluster via CLI.
The device has a reserved management interface and is accessible directly via the GUI using the reserved management IP.
config system fortiguard set fortiguard-anycast disable set protocol udp set port 8888 set sdns-server-ip 208.91.112.220 173.243.140.53 210.7.96.53 200.91.112.220 end
Note: The configuration must be manually applied in both appliances over the CLI console.
diagnose sys ha checksum recalculate
diagnose sys ha checksum cluster
If the cluster remains out of sync, the following sequence of commands should resolve the issue and restore the cluster to a synchronized state.
execute ha sync stop
fnsysctl killall hasync
Note: To confirm the daemon actually restarted, check its PID before and after with:
diagnose sys process pidof hasync
If the PID changes after fnsysctl killall hasync, the process was restarted.
execute ha sync start
diagnose sys ha checksum recalculate
Related article: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.