| Description | This article describes several problems that may arise when re-licensing a FortiGate-VM HA cluster and how to resolve them. |
| Scope | FortiGate-VM, FortiOS 7.x. |
| Solution |
When re-licensing a FortiGate-VM HA cluster the following issues might be observed:
The problems stem from the sequential license activation process in an HA cluster, which causes certificate regeneration and synchronization mismatches:
This results in invalid certificates, failed FortiGuard connections, and persistent HA sync issues.
To avoid certificate mismatches and ensure proper HA synchronization during license activation, use one of the following options:
Option 1: Simultaneous license upload.
Option 2: Enable HA override with priority.
Configure HA settings to enable 'override' and set a higher priority on the unit receiving the license first. This ensures the first unit becomes primary upon rejoining and overwrites certificates on the secondary, avoiding sync of old certificates.
config system ha
config system ha set priority 100
Proceed with license upload on Unit-A first, followed by Unit-B after the cluster stabilizes. After activation, verify HA sync status, certificate validity, and FortiGuard connectivity.
Option 3: Enable HA override with override-wait-time
On Unit-A:
config system ha After the reboot of Unit-A, FortiGates 'exchange' primary roles for clusters. So Unit-A will grab the master role back and stays that way until the override-wait-time period expires. This will cause the certificates to not be overwritten. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.