FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
kumarh
Staff
Staff
Article Id 416948
Description This article describes a situation where the Security Fabric displays a Disconnected status between a root FortiGate and a child FortiGate when the serial number of a secondary High Availability unit is used for authorization. It explains how to resolve the issue by using the primary FortiGate unit serial number.
Scope FortiGate.
Solution
  1. Ensure that the root FortiGate can communicate with the child FortiGate over the Security Fabric port.
    • Ping the child FortiGate:

 

execute ping <child_device_IP>

 

    • Telnet to the child FortiGate on port 8013 (default Security Fabric port).

 

execute telnet <child_device_IP> 8013

  1. Check CSF authorization and HA serial number. When authorizing the child FortiGate, if the following output appears.

 

diagnose sys csf authorization accept <FortiGate Serial Number>
csf_authorization_action Couldn't find pending entry for <FortiGate Serial Number>
action saved in system.csf.trusted-list

 

This output indicates that the serial number used for authorization may not belong to the primary HA unit.
The Security Fabric displays Disconnected when a secondary HA unit serial number is used.

image (3).png
The device configured for authorization must be the primary unit of the FortiGate. Security Fabric connections will not establish if a secondary or HA unit serial number is used.

image (1).png

 

  1. On the child FortiGate cluster, run the following command to confirm which device is the primary.

 

get system ha status

 

  1. Reauthorize the correct primary FortiGate serial number. On the root FortiGate, authorize the child FortiGate again using the primary unit serial number identified in step 3.

 

diagnose system csf authorization accept <FortiGate Serial Number>

 

  1. Verify the Security Fabric connection after authorizing with the correct primary unit serial number.

 

get system csf