Dear guys,
We have two FortiGate 300E in an active-active cluster. HA port is up, configuration sync is OK and everything looks fine.
But the slave device is unreachable. We cannot ping any interface on slave device when directly connecting the slave device to laptop. Ping reply is "destination host is unreachable".
Then I enabled load-balance-all through command line, but same result.
Do you have any suggestion?
Thanks
Solved! Go to Solution.
On the master unit, in CLI "exec ha manage 0" - can you login (telnet) across the HA link this way?
On the master unit, in CLI "exec ha manage 0" - can you login (telnet) across the HA link this way?
Hi,
Yes I could.
Any idea?
Hi,
In a A/A cluster you a have a primary unit and a subordinate unit (Slave)
The subordinate unit is not meant to process arbitrary traffic but only the sessions that are offloaded to the subordinate unit by the primary unit.
In order words, the session setup always happen on the primary unit, then the primary unit can decide to offload the session to the subordinate unit.
Regards
Radu
Hi,
Thanks for your answer, but even if I enabled load-balance-all? Or even by enabling sync packets?
In other words, no way for having two devices responsible to networks?
Thanks
No, you cannot have two devices that actively process traffic.
The primary unit receive the traffic and decide to load-balance to other subordinate unit if the criteria is matched.
For better understanding you can find all the details under the section: HA and load balancing
https://docs.fortinet.com/uploaded/files/4304/fortigate-ha-60.pdf
Regards
Radu
What you *can* do is manage them using a special management interface as mentioned here:
This is mainly so you can manage the second unit via GUI or for other monitoring(SNMP), but you can do what you need through CLI per Ede's response.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1742 | |
1114 | |
760 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.