Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
luca1994
Contributor

FGSP session monitor between FGCP clusters

Hello Team,

 

I have two FortiGate 2600F FGCP clusters (active/standby) with FGSP enabled between them for a specific VDOM. 

I would like to verify whether FGSP sessions are synchronized and see which ones are.

 

The following CLI commands appear to report FGCP session information only:

diagnose sys session sync

diagnose sys session list 

 

How can I retrieve session information for FGSP specifically?

 

Thanks in advance for the support

Best Regards 

4 REPLIES 4
AEK
SuperUser
SuperUser

Hi Luca

It is the same commands as you mentioned.

The sessions should have the session state "syn_ses", as described in this tech tip.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-FGSP-Configuration-Guide-for-Session-Sync-...

AEK
AEK
luca1994

Hello @AEK ,

 

sorry for the delay.

When I run the command diagnose sys session list | grep synced I also seem to see FGCP sessions. Perhaps there are specific flags to look for in the session status, but the official documentation does not mention them.
I also tried contacting Fortinet TAC, but other than sharing the commands in the KB article you sent me, they were unable to answer my questions.

The FGSP protocol is not well documented.
I would like to be sure that the sessions are synchronizing and, more specifically, how to proceed in case of troubleshooting.

 

Thanks in advance for the support

BR

 

wukantu1
New Contributor

Is it typically the same speed as the main lan/wan links on the firewall or can it be less? In this scenario there won’t be a massive amount of asymmetric traffic due to the way the routing is being done.

router login 192.168.l.l
AEK
SuperUser
SuperUser

Hi Luca

The document mentions the flag "syn_ses", not "synced".

If I remember well, synced is seen on the FG that first handled the session, while syn_ses is seen on the peer FGT that received the session info from the first FGT.

You can check from the GUI on FortiView sessions, use filter to select some sessions, you should see exactly the same sessions on both FortiGates, that means sessions are synchronized.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors