Created on 08-19-2022 07:19 AM Edited on 02-13-2024 08:57 PM By Anthony_E
Description | This article describes how to configure FortiManager to use custom certificate for HA communication on port 5199. |
Scope |
FortiManager v6.2.7 and above,v6.4.x, v7.0.,v 7.2.x. |
Solution |
By default, communication between FortiManager in HA cluster is works on TCP port 5199. Once HA is enabled, all active interfaces on the primary FortiManager will be opened and actively listening to port TCP/5199. However, it will only react to those peer with the configured Serial Number and packets coming from the configured IP address.
By default, all HA communication will be using the default 'Fortinet_Local' certificate. Starting from firmware 6.2.7, an extra feature is added to allow administrator to configure the custom certificate to be used for HA communication. The CLI command as below:
config system ha set local cert "certificate_name" end
However, there are two things to take note:
Below is the recommended step-by-step configuration:
Configure HA to use this custom certificate for TCP port 5199 using the following commands.
config system ha set local cert "certificate_name" end
diagnose ha stats
Below is the sample output from the primary unit if the cluster is up:
diagnose ha stats cluster status: up --- cluster member information --- ip : 10.197.1.194 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.