Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
flamer
New Contributor II

Adding HA cluster to fortimanager

Hi all,

 

I have tried adding an HA fortigate cluster to the fortimanager, using the dedicated management interface (have tried outside and inside interface aswell with same issue)

 

When adding, it detects the cluster, finds the name and IP and the fact its a cluster ETC then at this stage I get the error:

(success) Discovering device (success)Creating device database (success)Initializing configuration database (FAIL) Retrieving configuration Retrieving support data Updating group membership Successfully add device

 

with error: "Failed to reload configuration. duplicate"

 

Anyone know why this is occurring? Can't find much relating to this particular error.

 

 

7 REPLIES 7
chall_FTNT
Staff
Staff

Did you check the device list to see whether any of the cluster members already showed up in the list as standalone prior to adding the cluster?

Chris Hall
Fortinet Technical Support
scao_FTNT

may I know the FMG and FGT version?

 

Thanks

 

Simon

flamer
New Contributor II

chall wrote:

Did you check the device list to see whether any of the cluster members already showed up in the list as standalone prior to adding the cluster?

Yes there is nothing with same name, SN or IP

 

scao_FTNT wrote:

may I know the FMG and FGT version?

 

Thanks

 

Simon

FGT = v5.4.1,build1064 (GA)

FMG = v5.6.0-build1557 170727 (GA)

 

thanks!

scao_FTNT

thanks for the info, we noticed FMG 5.6.0 has some issue to add a FGT HA config with this duplicate error, if possible, not sure if you can provide me the FGT HA config part, so we can double check and confirm the fix for next 5.6.1 release

 

Thanks

 

Simon

flamer
New Contributor II

Hi Simon,

 

Here is config, we can attempt to change some settings if you think there is a workaround.

 

 

regards

 

 

config system ha set group-id 60 set group-name "XXXXXX-Cluster" set mode a-p set password ENC xxxxx set hbdev "port31" 50 "port32" 50 set session-pickup enable set ha-mgmt-status enable set ha-mgmt-interface "mgmt1" set ha-mgmt-interface-gateway 10.111.xx.xx set override disable set priority 200 set monitor "INSIDE_LAG" "TRANSITS-LAG" "port17" set ha-direct enable end

scao_FTNT

From investigation, this failed reason may not related to HA but because of duplicate entry in "config webfilter urlfilter", FMG added a check in 5.6.0 for this duplicate and if you can find a same name URL entry configured in same url filter table, pls try to remove that entry and see if retrieve works

 

Thanks

 

Simon

 

flamer
New Contributor II

thanks yes that did the trick, we had a few duplicate URL's across different profiles, removed them and it now adds without error.

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors