Description | This article describes how to troubleshoot when the cluster shows 'out of sync' with the following message: 'firewall.policy'. |
Scope | FortiGate. |
Solution |
Go to System -> HA and check if the secondary firewall is out of sync. Hover over the status, and it will show that it is out of sync due to 'firewall.policy'.
The difference can be checked through the CLI using the following command, which will provide the checksum of each policy:
diagnose sys ha checksum show <vdom_name> firewall.policy<----- Run this command on both FortiGates in the cluster.
For example, the command would be: diagnose sys ha checksum show root firewall.policy
The output from each FortiGate should then be compared to check for any differences in the checksum.
As shown in the figure above, a difference is detected, and the ID referenced corresponds to the firewall policy ID. In this case, it is the firewall policy with ID 9. Review and edit the firewall policies that do not match to identify any differences. Once the discrepancies are resolved, the HA pair will synchronize again.
Related articles: Troubleshooting Tip: HA synchronization issue, cluster out of sync |