Created on
09-25-2025
05:37 AM
Edited on
10-22-2025
09:40 PM
By
Anthony_E
| Description | This article describes the issue when the WAN port shows as up but is not passing traffic on SD-WAN with HA A-A. |
| Scope | FortiGate. |
| Solution |
Issue: The WAN interface is showing as inactive, but the interface status appears up.
FW01 # diagnose hardware deviceinfo nic
Troubleshooting steps:
get router info routing-table details 0.0.0.0
execute ping-options source 14.98.4.78
Run the below command and verify if the default Group ID 0 is in use:
get system ha status
If using the default Group ID, there is a chance it could conflict with a different cluster on the same ISP due to the way the Virtual MAC address is calculated: Technical Tip: Changing MAC address on WAN interface for a HA cluster
Below update after configuration change of group ID to 128.
FGT201F-2 # get system ha status
Once a group ID was configured/added, the last 4 octets of the virtual MAC address were derived from the group ID. After that, ping to the gateway should resolve. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.