FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Nivedha
Staff
Staff
Article Id 240140
Description This article discusses about HA devices that are out of sync after a firmware upgrade.
Scope FortiGate.
Solution

While upgrading HA using Uninterrupted upgrade, both devices should upgrade simultaneously:

 

https://docs.fortinet.com/document/fortigate/6.2.3/cookbook/247944#:~:text=upgrade%2Dtool).-,Uninter...

 

After the upgrade device may be out of sync when the following occurs:

 

1) Only one of the devices is upgraded to the next firmware version.

 

For example: if upgrading HA devices from 7.0.1 to 7.0.3, the primary gets upgraded to 7.0.3 and the secondary stays in 7.0.1 then:

 

    a) Boot primary device to the previous version by selecting the alternate firmware version to boot.

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Selecting-an-alternate-firmware-for-the-ne...

 

OR

 

   b) Remove the secondary from the cluster (https://community.fortinet.com/t5/FortiGate/Technical-Note-Disconnecting-a-member-from-a-cluster/ta-...), upgrade the secondary device and join it back to the cluster.

2) Due to configuration differences, recalculate HA checksum using : diag sys ha checksum recalculate

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Troubleshooting-a-checksum-mismatch-in-a-F...


Wait for 5 mins, if the issue is still not resolved, open a ticket to technical support.