FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
ssanga
Staff & Editor
Staff & Editor
Article Id 350303
Description

This article describes the behavior where the SD-WAN rules page fails to load on the secondary device in an HA (High Availability) cluster.

Scope

FortiGate v7.2.6, v7.2.7, v7.2.8, v7.4.4.

Solution

The SD-WAN Rules GUI page does not load on the secondary device in an HA setup, while it loads fine on the primary unit.

Secondary Unit:


secondaryunitHA.png
Primary Unit:

 

primaryunitHA.png


This is an expected behavior because to virtual-wan/health-check monitor API is not allowed on an HA secondary FortiGate. From v7.4.8, v7.6.1, and later, a GUI message was added to show this behavior.

When the SD-WAN rule menu is opened on the GUI on the HA secondary unit, the message 'Cannot view SD-WAN Rules table on an HA Secondary FGT' will be shown instead.

ScreenHunter 1326.png

 

For any other issue, the following information will be required by FortiGate TAC for Investigation:

  1. TAC Report: 'execute tac report'.
  2. Screenshots.
  3. Fortinet Support Tool data: Troubleshooting Tip: Collect GUI slowness and errors debugs via Fortinet Support Tool
  4. The configuration file of the FortiGate.

 

Related article:

Technical Tip: SD-WAN rule page keeps on loading on the secondary GUI when accessing through dedicat...