Description | This article describes the cause and resolution for the error 'Cannot reassign primary private IP addresses' seen in the OCID debug output during Oracle Cloud Infrastructure (OCI) FortiGate HA failover. |
Scope | FortiGate, OCI |
Solution |
In OCI, only secondary private IP addresses on a VM’s Virtual Network Interface Card (VNIC) can be reassigned between interfaces (attach/detach). This limitation means that FortiGate HA configurations should avoid using the primary private IP of the OCI VNIC for FortiGate interface configurations.
OCI VMs are assigned one primary private IP address and can have additional secondary private IPs. FortiGate HA configurations should use secondary IPs from the OCI VM, not the primary IP. Attempting to assign the primary IP of an OCI VNIC to a FortiGate interface will trigger a 'Cannot reassign primary private IP addresses' error.
When this error is observed during a failover, it indicates that the primary private IP address of the OCI VM VNIC has been configured on a FortiGate interface.
To check for this error, use the following debug commands on FortiGate:
diagnose debug application ocid -1
-----output clipped---------
Resolution:
|
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.