Description | This article explains the behavior of OSPF routing refreshes when configuring HA active-passive with a monitored port. |
Scope | FortiGate v7.0, v7.2, and above. |
Solution |
Here is the example of FortiGate with active-passive and monitored port configured.
FGT1 is connected to switch1 via port2. FGT1 # get router info routing-table ospf
When the switch1 device fails/shuts down, the FortiGate will trigger the HA monitor port. Thus, it will failover from FGT1 to FGT2 for a few seconds and switch back to the FGT1 as a primary due to the value of the monitored port being the same.
This behavior will cause the OSPF routing to refresh and cause a longer downtime, which defeats the purpose of having an ECMP link to the destination on FGT1.
To maintain the route without triggering the failover, we need to enable the configuration below:
config system ha
The OSPF routing will not refresh, and FGT1 will continue to direct traffic to port3 via switch2 when switch1 is down. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.