We have two FortiGate Firewalls(200F) and HA is setup. from a month back the Secondary firewall showing not sync. we contacted FortiGate support, the support tried to re-sync secondary firewall but failed. Now support respond:
1- Shared documents with us for HA creation
2- Downtime required 1 hour downtime.
Do we really need a downtime ?
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
Thank you for your question. It depends, if there will be any action on primary device, then yes.
But if you will be recreating HA only on secondary device (factory reset, adding it to HA, etc) then you just need to be careful to correctly set HA priority, to keep primary device primary then you should not have any problems. My guess is that is just precaution.
Thanks Akristof for your response. I need concrete words because its a production and we need to be very careful in recreating new HA. is it possible that I can get a step by step guide
No one can guarantee anything anyway anyhow. But if you share the procedure the TAC supplied to you (delete identifiable info first), may be someone will be able to comment.
Once you configure the HA on the Fortigate, a virtual mac is generated and assigned to each interface of the primary cluster member(not applicable to the HA mgmt interface).
https://docs.fortinet.com/document/fortigate/6.0.0/handbook/996579/cluster-virtual-mac-addresses
If the switching environment to which the cluster members are connected fails to update the cam tables with the new mac address, you might observe an outage in network connections flowing through the Fortigate cluster.
In case if you face an outage after setting up the cluster, please start troubleshooting by double-checking the cam tables of the switched and proper arp resolution.
Ahmad
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1502 | |
1011 | |
749 | |
443 | |
209 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.