Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
ZAHIDHASEEB
New Contributor III

Does Downtime required if recreate HA

We have two FortiGate Firewalls(200F) and HA is setup. from a month back the Secondary firewall showing not sync. we contacted FortiGate support, the support tried to re-sync secondary firewall but failed. Now support respond:

1- Shared documents with us for HA creation

2- Downtime required  1 hour downtime.

Do we really need a downtime ?

4 REPLIES 4
akristof
Staff
Staff

Hi,

Thank you for your question. It depends, if there will be any action on primary device, then yes.

But if you will be recreating HA only on secondary device (factory reset, adding it to HA, etc) then you just need to be careful to correctly set HA priority, to keep primary device primary then you should not have any problems. My guess is that is just precaution.

Adrian
ZAHIDHASEEB
New Contributor III

Thanks Akristof for your response. I need concrete words because its a production and we need to be very careful in recreating new HA. is it possible that I can get a step by step guide

Yurisk
SuperUser
SuperUser

No one can guarantee anything anyway anyhow. But if you share the procedure the TAC supplied to you (delete identifiable info first), may be someone will be able to comment. 

Yuri https://yurisk.info/  blog: All things Fortinet, no ads.
Yuri https://yurisk.info/ blog: All things Fortinet, no ads.
aahmadzada
Staff
Staff

Once you configure the HA on the Fortigate, a virtual mac is generated and assigned to each interface of the primary cluster member(not applicable to the HA mgmt interface).
https://docs.fortinet.com/document/fortigate/6.0.0/handbook/996579/cluster-virtual-mac-addresses
If the switching environment to which the cluster members are connected fails to update the cam tables with the new mac address, you might observe an outage in network connections flowing through the Fortigate cluster.

In case if you face an outage after setting up the cluster, please start troubleshooting by double-checking the cam tables of the switched and proper arp resolution.

 

Ahmad

 

Ahmad
Labels
Top Kudoed Authors