Hello,
I need advice on a problem, or to make sure that this is indeed the case. I have a FG VM in a cluster (FortiOS 7.0.14) and I updated the license from 2CPU to 4CPU but only on the Master (Master 4CPU, Slave 2CPU). HA worked correctly and everything worked but after 24 hours the cluster stopped working and blocked all communication with a message: VM resource exceeds license limit. Master/Slave must have the same license? (number of CPUs)
Thx :)
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello @Alfonziino ,
Licenses and models of devices in HA must always be the same. So you should upgrade its license on the slave device.
The conditions for configuring HA are as follows:
Devices must be of the same model.
Devices must have the same Firmware version.
The same licenses must be applied to all devices on the cluster.
https://community.fortinet.com/t5/FortiGate/Technical-Tip-Basic-HA-Setup/ta-p/191959
Hello @Alfonziino,
Thank you for reaching out Fortinet support.
In order to have HA working on cloud, you need to have same licenses and CPU settings.
Kindly get your secondary on the same level and then bring them in HA pair.
Best Regards,
Piyush
Hello,
thanks for your advice... but one thing I don't understand: FG is VM64 (not VM04) in HA and the licenses have the same subscription. The only difference is that the Master has 4 CPUs and the Slave has 2 CPUs. The strange thing is that after updating the license on the Master box to 4 CPU everything worked for 24 hours (HA worked correctly, Master worked on 4 CPU, Slave on 2 CPU) but after 24 hours the FG blocked all traffic.
The question is: is it a requirement to have the same license on the FG VM64 in HA with the same number of CPUs on Master and Slave? (is there documentation for this?) Because if the problem were that the Master has 4 CPUs and the Slave 2 CPUs, then I will not synchronize the boxes and HA will not be functional from the first moment, right?
VM64 = Virtual Machine 64Bit Platform (Platform description)
VM02 = VM allowing 2 CPU's (Licens Description)
VM04 = VM allowing 4 CPU's (Licens Description)
Hello @Alfonziino ,
You can think of licensing from Fortinet's perspective like this. Fortigate VM64 is just a deployment style. VM04 and VM02 are the model number of that deployment.
When you look at it this way, it seems like you are trying to use FortiGate 100F and FortiGate 200F in the same cluster structure. That's why HA is not established.
But HA is established and everything worked but only for 24 hours and I don't understand why :(
Seems like a Graceperiode. So you have time to apply a new licens to the other FG/VM.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1661 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.