FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
cravikumar
Staff
Staff
Article Id 425481
Description This article describes why the device does not reflect as an HA cluster being selected in the automation stitch on the security fabric root.
Scope FortiGate.
Solution

When trying to add the current HA cluster in the FortiGate(s) of the automation stitch, it fails to save changes without any error message. 

 

un1 (2).gif

 

This can happen because the value of 'set ha-group-id' under 'config system automation-destination' does not match the value 'set group-id' under 'config system ha'. 

 

config system ha
    set group-id 1  
<--------
    set group-name "HA-Group"
    set mode a-p

end

 

config system automation-destination
    edit "Restart WAD due to Memory"
        set type ha-cluster
        set destination "HA-Group"
        set ha-group-id 2  
<------
    next

end


Correcting the ha-group-id to match those of the HA group-id settings will allow the settings to be saved successfully.

Additionally, it is expected that FortiOS generates new entries within 'config system automation-destination' when the destination is configured or modified. See this article for more info: Technical Tip: Behavior of automation stitch on a HA cluster and use of automation-destination.