I am experiencing a connectivity issue where the Secondary unit of a FortiGate HA cluster cannot connect to the FortiAnalyzer (FAZ).
Environment:
Device: FortiGate HA Cluster (Active-Passive)
Log Storage: FortiAnalyzer (FAZ)
Symptoms:
The Primary FortiGate connects to the FAZ normally.
The Secondary FortiGate shows a status error: "Could not connect to the FortiAnalyzer to retrieve its serial number."
On the FAZ side, both devices appear in the device list, but the Secondary unit is not sending logs correctly.
Troubleshooting Performed:
Certificate: Disabled "Verify FortiAnalyzer certificate", but the issue persists.
HA-Direct: The ha-direct setting is currently disabled.
Packet Capture: Ran diag sniffer packet any "host [FAZ_IP]" 4 0 l on the Secondary unit. Results: No packets were captured at all when attempting to connect to the FAZ.
The Secondary unit seems unable to initiate any traffic toward the FAZ IP.
Hi @qoo55253 ,
- Ensure that the HA configuration is correct and that the secondary unit is properly configured to communicate with the FortiAnalyzer.
- Check if the HA management interface is configured and if the gateway is set correctly on the secondary unit.
- Confirm that the network configuration allows the secondary unit to reach the FortiAnalyzer.
- Run the following debug commands on the secondary unit
diagnose debug application miglogd 255
diagnose debug enable
- Verify that the secondary FortiGate is authorized by the FortiAnalyzer.
Best regards,
Erlin
| User | Count |
|---|---|
| 2914 | |
| 1452 | |
| 852 | |
| 826 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.