FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
edyrmishi
Staff
Staff
Article Id 378139
Description This article describes how, when a RAID-enabled FortiGate joins an existing cluster, the primary unit shuts down automatically with the message 'secondary and primary have different hdisk status, Shutdown the box!'
Scope FortiGate.
Solution

A known issue has been observed when a FortiGate with RAID enabled joins an existing cluster. The primary FortiGate in the cluster shuts down automatically and displays the following message:

 

secondary and primary have different hdisk status, Shutdown the box!

 

This occurs regardless of HA uptime, priority, or serial number. When a FortiGate with RAID enabled joins, it takes precedence over other cluster members and forces them to shut down.

 

Reproduction Scenario:

 

  1. A new HA is cluster deployed with the HA port disabled or disconnected.
  2. FGT-Primary is configured with a priority of 128, uptime greater than 5 minutes, and RAID disabled.
  3. FGT-Secondary is configured with a priority of 64, uptime of 2 minutes, and RAID enabled.
  4. HA port connected/enabled - this causes the primary FortiGate to shut down.
  5. A power cycle is required to bring the primary FortiGate back online.

 

This issue is has been reported under ID 1098192 and a fix will be provided in FortiOS 7.6.3.

 

For FortiOS versions prior to this release, it is essential to verify and configure RAID settings properly before adding a FortiGate device to the cluster to avoid unexpected shutdowns.

 

The following commands are helpful in identifying Disk and RAID status:

 

  • List disk devices and partitions:

 

image.png

 

  • Display information about all of the disks:

 

image.png

 

  • Check the Raid status:
  • Raid enabled:

 

image.png

 

  • Raid disabled:

 

image.png

 

More information can be found in the FortiGate Administration Guide.