Description | This article describes how to recover synchronization in the HA cluster member when there are too many checksum differences in tables compared to primary node. |
Scope |
FortiGates in HA environment |
Solution |
For testing purposes, FortiGate-500E v7.0.15, build0566, 231024 is used.
show full sys ha
get system status
The collected information shows as follows (output truncated for better readability):
Initial notes:
Activity Summary:
Procedure:
Note: If the cables are not labeled, proceed to identify them to avoid confusion when reconnecting them later.
Note: If there is no access to the secondary member through the GUI, these changes must be performed through the serial console connection, but first the configuration must be restored using a TFTP server. More information in the following technical document: Technical Tip: Restoring a config file from the CLI by using TFTP server
config system global
config system ha
Check from the CLI that the changes have been accepted:
show full system global | grep hostname <- FortiGate-B should be the hostname. show full system ha | grep priority <- 100 should be the Priority.
If the units DO NOT sync, open a ticket with support and call support for immediate assistance.
For more information on how to troubleshoot a checksum mismatch on HA clusters, see Troubleshooting Tip: Troubleshooting a checksum mismatch in a FortiGate HA cluster. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.