Good morning team.
It is required to change the fortigate firewall from Master to Slave (slave to master), could you tell me if this action is performed from the GUI or from the CLI? I would appreciate it if you could share with me some document of the steps to be taken, since this is the first time I am going to perform this action and I am afraid of accidentally turning off the equipment.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Just a single command if uptime difference is more than 5 min and your're not using priority/override.
diag sys ha reset-uptime
Like in the KB:
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Restoring-HA-master-role-after-a-failover-...
<edit>
also make sure you have below config:
config system ha
set session-pickup enable
end
</edit>
Toshi
Hello unknown1020,
In addition here are additional ways you can perform a failover:
If override is disabled which is by default you can force failover by reset ha uptime on primary
diag sys ha reset-uptime
If override is enabled you can force failover by changing priority in GUI or CLI.
You may failover via CLI by following this KB link: https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-use-failover-flag-to-change-Active-...
Here's also a KB that explained about HA age time difference for reference
https://community.fortinet.com/t5/FortiGate/Technical-Tip-HA-age-time-difference-HA-cluster-uptime/t...
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1640 | |
1069 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.