Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Ahmedaz
New Contributor

Accessing HA secondary via MGMT link and OOB VDOM

Hello Engineers

i have 2 601F in HA cluster (Active/Standby).

There is a cable between the OOB-SW to each 601F into the MGMT port on the same VLAN.

i need to access the FortiGate directly , when connect my laptop to the Firewall Primary one in MGMT port i can ping and i can login via GUI ,

BUT, when connect my laptop to the Firewall Secondary one in MGMT port i can`t ping and i can`t login to the GUI also , when i connect my laptop to secondary firewall also disconnect the MGMT port on Primary Firewall .

the another issue is

yesterday, i upgrade the Firmware of firewalls in (HA Mode) when the Primary on reboots the Secondary become the Primary as well as but what i noticed it i can reach internet via VDOM " INTERNET "

BUT, Also i can`t Reach the MGMT IPs of the switches and servers in VDOM " OOB "

After the First firewall finish the Reboot it Becomes the Primary and the i Can Reach the MGMT IPs of the switches and servers.

So i think the issue is between the OOB Switch and the second Firewall

SO And advices to TSHOOT this issue ?

Thanks to all

1 Solution
ozkanaltas
Valued Contributor II

Hello @Ahmedaz ,

 

Did you do dedicated management port settings on HA? 

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGate-dedicated-mgmt-feature-Out-of-ba...

 

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW

View solution in original post

If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
3 REPLIES 3
ozkanaltas
Valued Contributor II

Hello @Ahmedaz ,

 

Did you do dedicated management port settings on HA? 

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGate-dedicated-mgmt-feature-Out-of-ba...

 

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
Ahmedaz

NO in HA setting just the HA links , so what should i do ?

 

ozkanaltas
Valued Contributor II

Hello @Ahmedaz ,

 

If you want to access each FortiGate GUI, you need a dedicated management configuration. 

 

This document tells how you can configure dedicated management.

 

https://community.fortinet.com/t5/FortiGate/Technical-Tip-FortiGate-dedicated-mgmt-feature-Out-of-ba...

 

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors