We have Fortinet 600E Firewall in High availability configuration. Recently we have configured our new Fortinet manager in high availability with VRRP setup because both Fortinet managers are in different subnet and in different Geo location.
After completing the Fortinet manager setup when I add my Fortinet Firewall in Fortinet manager (primary) everything looks good so in my next step I do a Failover of my Forti Manager and After Failover I notice out of my two one of the firewall show unreachable. I try to install a policy it fails. then I try to push the system configuration, now here when I try to push the system configuration a major issue notice that all my running traffic stop working and I am not able to access my firewalls. then when I take a console access to the firewall I notice my HA was break (On hardware also HA LED was off) both firewalls are in stand alone state. so I restart my first primary firewall and then my traffic became normal and the primary firewall shows primary but the second firewall became stand alone and show no HA configuration.
I need to understand where it goes wrong. why my firewall HA was break. Firewall HA is configured long time back and we tested firewall failovers many time before.
The only last change we done is push system configuration which triggers the firewall HA Failure
Which FortiOS version, and which FortiManager version?
Are you managing the FortiGate from a HA shared interface/IP (that is under HA control), or from HA-reserved management interface?
Forti Firewall version is 7.4.9 and Forti Manager version is 7.4.8
managing HA from reserved management interface.
Versions are fine.
But as per my knowledge it is wrong to manage the FGT from reserved management interface, and your issue is probably caused by this configuration.
Try manage it from a regular HA shared interface and IP other than the reserved mgmt.
| User | Count |
|---|---|
| 2839 | |
| 1436 | |
| 812 | |
| 796 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.