Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
qoo55253
New Contributor

Connectivity issue between Secondary FortiGate and FortiAnalyzer in HA cluster

I am experiencing a connectivity issue where the Secondary unit of a FortiGate HA cluster cannot connect to the FortiAnalyzer (FAZ).

Environment:

Device: FortiGate HA Cluster (Active-Passive)

Log Storage: FortiAnalyzer (FAZ)

Symptoms:

The Primary FortiGate connects to the FAZ normally.

The Secondary FortiGate shows a status error: "Could not connect to the FortiAnalyzer to retrieve its serial number."

On the FAZ side, both devices appear in the device list, but the Secondary unit is not sending logs correctly.

Troubleshooting Performed:

Certificate: Disabled "Verify FortiAnalyzer certificate", but the issue persists.

HA-Direct: The ha-direct setting is currently disabled.

Packet Capture: Ran diag sniffer packet any "host [FAZ_IP]" 4 0 l on the Secondary unit. Results: No packets were captured at all when attempting to connect to the FAZ.

The Secondary unit seems unable to initiate any traffic toward the FAZ IP.

1 REPLY 1
esalija
Staff
Staff

Hi @qoo55253 ,

 

- Ensure that the HA configuration is correct and that the secondary unit is properly configured to communicate with the FortiAnalyzer.
- Check if the HA management interface is configured and if the gateway is set correctly on the secondary unit.
- Confirm that the network configuration allows the secondary unit to reach the FortiAnalyzer.
- Run the following debug commands on the secondary unit
diagnose debug application miglogd 255
diagnose debug enable

- Verify that the secondary FortiGate is authorized by the FortiAnalyzer.

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-FortiGate-in-HA-unable-to-connect-to...

Best regards,
Erlin

 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors