Created on
09-04-2025
11:50 PM
Edited on
09-23-2025
12:15 AM
By
Jean-Philippe_P
| Description | This article describes how to fix the system interface error in HA on VM setup. |
| Scope | FortiGate. |
| Solution |
Issue: The setup is HA Active-Passive (A-P) in a virtual machine (VM) environment. When HA goes out of sync due to a system interface error, both the primary and secondary devices show different IP addresses instead of the same.
Solution: When this error occurs, the following changes can be made to resolve the issue:
config system vdom-exception
Once the above changes are applied, the HA status will show sync status:
Note: Since this is purposefully done in a VM environment, where both devices have different IP addresses and default routes. So, before making the VDOM exception check it with the cloud team because this might sync the unwanted settings between HA members, which could cause the complete setup to stop working. In VM setup, the interfaces have different IP addresses, unlike in On-Prem setup, mostly if both devices are in different availability zones (which is true in most cases).
Related document: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.