Description | This article discusses HA devices that are out of sync after a firmware upgrade. |
Scope | FortiGate. |
Solution |
While upgrading HA using Uninterrupted upgrade, both devices should upgrade simultaneously:
After the upgrade device may be out of sync when the following occurs:
For example, if upgrading HA devices from v7.0.1 to v7.0.3, the primary gets upgraded to v7.0.3, and the secondary stays in 7.0.1, then:
Technical Tip: Troubleshooting a checksum mismatch in a FortiGate HA cluster
execute ha synchronize stop diagnose sys ha checksum recalculate
diagnose debug disable --> To stop the debugs.
Allow a couple of minutes to verify the differences in the cluster.
Troubleshooting Tip: Allocate config disparity for HA out-of-sync Procedure for HA manual synchronization - Fortinet Community Note:
show full system ha | grep uninterruptible-upgrade
From FortiOS v7.4.1 and later, the option uninterruptible-upgrade has been replaced with upgrade-mode. config system ha set upgrade-mode {simultaneous | uninterruptible | local-only | secondary-only} end
The default setting for upgrade-mode is uninterruptible, which follows the same behavior as the previous set uninterruptible-upgrade enable. Similarly, the behavior of set uninterruptible-upgrade disable is now mapped to set upgrade-mode simultaneous.
Related article: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.