Created on
07-01-2025
04:43 AM
Edited on
07-01-2025
04:44 AM
By
Jean-Philippe_P
Description | The article describes how to fix the HA out-of-sync issue caused by 'chattr sync-disable server' option under RADIUS settings. |
Scope | FortiMail. |
Solution |
After upgrading to v7.6.3, FortiMail HA goes out-of-sync with the below RADIUS configuration.
config profile authentication radius end
The sync-disable option is used to modify the default synchronization behavior of attributes, preventing them from being automatically replicated to other cluster members.
However, it results in the HA going out of sync.
HAsyncd debug:
hasyncd: config_receive: problem running CLI command, error code: -56, errstr: Empty value is not allowed, CLI: config profile authentication radius edit Clearpass_205 set secret abcd set auth-prot pap next
Workaround: Among all the attributes in 'config profile authentication radius', only 'chattr sync-disable server' triggers this issue.
To fix this issue, apply the workaround below and reboot the FortiMail unit:
config profile authentication radius
It resolves the HA sync issue.
As 'server' is a must-have attribute, it should not be set as sync-disable. This issue will be resolved in FortiMail versions 7.4.6, 7.6.4, and 8.0.0. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.