Created on
07-23-2025
02:25 AM
Edited on
07-24-2025
06:53 AM
By
Jean-Philippe_P
Description | This article describes how to troubleshoot when the cluster shows 'out of sync' due to Antivirus profile mismatch. |
Scope | FortiGate. |
Solution |
Go to System -> HA and check if the secondary firewall is out of sync. Hover over the status, and it will show that it is out of sync due to 'antivirus.profile'.
The difference can be checked through the CLI using the following command, which will provide the checksum for all the available antivirus profiles in the current Firewall:
diagnose sys ha checksum show <vdom_name> antivirus.profile <----- Run this command on both FortiGates in the cluster.
For example, the command would be: diagnose sys ha checksum show root antivirus.profile
The output from each FortiGate should then be compared to check for any differences in the checksum. 'FGT1':
'FGT2':
As shown in the figure above, Default_PT has a different hash value on both the HA peers.
To identify what exactly is not matching in the Default_PT antivirus profile, the below checksum can be verified on both peers.
diagnose sys ha checksum show root antivirus.profile Default_PT
Run the same command on both primary and secondary devices, and it will reflect what exactly under Default_PT is not matching. Review and edit the Antivirus Profile that does not match to identify any differences. Once the discrepancies are resolved, the HA pair will synchronize again.
Related article: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.