FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
dalcoba
Staff
Staff
Article Id 371141
Description This article describes how to troubleshoot when the cluster shows 'out of sync' with the following message: 'firewall.policy'.
Scope FortiGate.
Solution

Go to System -> HA and check if the secondary firewall is out of sync. Hover over the status, and it will show that it is out of sync due to 'firewall.policy'.

 

The difference can be checked through the CLI using the following command, which will provide the checksum of each policy:

 

diagnose sys ha checksum show <vdom_name> firewall.policy<----- Run this command on both FortiGates in the cluster.

 

For example, the command would be:

diagnose sys ha checksum show root firewall.policy

 

The output from each FortiGate should then be compared to check for any differences in the checksum.

 

Compare.png 

As shown in the figure above, a difference is detected, and the ID referenced corresponds to the firewall policy ID.

In this case, it is the firewall policy with ID 9.

 

Review and edit the firewall policies that do not match to identify any differences. Once the discrepancies are resolved, the HA pair will synchronize again.

 

Related articles:

Troubleshooting Tip: HA synchronization issue, cluster out of sync

Technical Tip: Procedure for HA manual synchronization

Contributors