Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
redhat9
New Contributor

Choice between active/active and active/passive mode FORTIGATE 50E

Hi, i have setup active active cluster fortigate 50E but ha is out of sync.

 

i found a littleexplanatin to setup this cluster in coobook but it's not a complete tutorial and it's my first time with cluster fortinet.

 

can you explain me in details how to setup active/active cluster and i want to know if it's respond to my need in fact or perhaps active/passive is more adapt to my needs.

 

Regards

6 REPLIES 6
ede_pfau
SuperUser
SuperUser

Cluster not synchronizing has nothing to do with the HA mode.

For debugging use the CLI and these instructions from the kb.fortinet.com:

"Technical Note: Troubleshooting a checksum mismatch in a FortiGate HA cluster"

 - in newer versions of FortiOS, the command is "diag sys ha check clu [|global|root]"

 

Comparing the list of CRCs of each config category will show you where the difference in config is. Compare the config files from master and slave for this section and correct it.

 

"diag sys ha checksum recalc" will sometimes help as well.

 

For the HA mode, my feeling is that 90% of all clusters run in a-p mode because the benefits of a-a are not crucial or needed then. Less resources, less HA traffic, not so much less throughput (which would be the strongest argument pro a-a mode).

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
redhat9

Hello. Thanks a lot for your reply. I talk with my collegue and we need just ha activé passive. I have to go to datacenter to setup. Regards.
ede_pfau

you'll see it's not a big deal to change the mode. Would you please report if it caused a reboot? Not sure about it.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Yurisk

If you are not sure then you do NOT need Active/passive mode. Switch to A-P and everything will just work. 

Yuri https://yurisk.info/  blog: All things Fortinet, no ads.
Yuri https://yurisk.info/ blog: All things Fortinet, no ads.
ede_pfau

@Yurisk: ??

I was not sure if changing the setting will cause a reboot. Just curious.

Ede Kernel panic: Aiee, killing interrupt handler!
Ede Kernel panic: Aiee, killing interrupt handler!
Yurisk

@ede_pfau - no idea either, never had to change mode to A/A on working gear, actually - never had to use Active-Active in Fortigates in production, I strive to solve/prevent problems, not to create them, who wants load balancing - have load balancers for that :)  

Yuri https://yurisk.info/  blog: All things Fortinet, no ads.
Yuri https://yurisk.info/ blog: All things Fortinet, no ads.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors