Hi everyone, I'm having a very unusual problem. I have a FortiGate cluster on IBM Cloud, version 7.6.2. Node 1 and Node 2. Node 1 had a RAM problem, rebooted, and failed over to Node 2, so far, no problems. I kept Node 2 active while we replaced the RAM. The problem is that, after replacing the RAM, whenever I try to fail over to return Node 1 to active, the network gets extremely intermittent, several pings are lost, many systems can't communicate, and BGP neighbors won't connect. Of course, I've checked everything I could think of, the HA configurations are correct, and the boxes are syncing without any issues. Has anyone else experienced a similar scenario?
Could you share the logs related to BGP after the switch-over?
I think by checking the BGP details, we might be able to identify something related to the issue
Regards
Bill
Unfortunately, I didn't collect this information. Since it's a critical environment, I had to return quickly. I only had time to notice the nodes down. But not only in the outlying neighborhoods, packets where the firewall is the network gateway also didn't work.
VRF 0 BGP router identifier 10.14.17.106, local AS number 65103
BGP table version is 2
13 BGP AS-PATH entries
0 BGP community entries
Neighbor V AS MsgRcvd MsgSent TblVer InQ OutQ Up/Down State/PfxRcd
169.254.169.1 4 4201065570 19 24 2 0 0 00:15:55 16
169.254.169.9 4 4201065536 0 0 0 0 0 never Connect
169.254.169.17 4 4201065536 0 0 0 0 0 never Connect
169.254.169.25 4 4201065570 19 22 2 0 0 00:15:51 1
169.254.169.33 4 4201065536 0 0 0 0 0 never Connect
169.254.169.41 4 4201065570 19 20 1 0 0 00:15:50 1
169.254.169.49 4 4201065536 0 0 0 0 0 never Connect
169.254.169.57 4 4201065570 19 22 2 0 0 00:15:51 1
169.254.169.65 4 4201065570 0 0 0 0 0 never Connect
169.254.169.81 4 4201065570 18 22 2 0 0 00:15:50 1
169.254.169.97 4 4201065536 0 0 0 0 0 never Connect
169.254.169.105 4 4201065536 18 22 2 0 0 00:15:49 1
Maybe try a full session table clear and a reboot of both nodes after the RAM swap? Also double-check the HA heartbeat and link monitoring sometimes a single missed heartbeat can cause the exact kind of intermittent traffic you’re seeing.
Could you share the ticket number ? I could get some information from that to check the issue. Thanks
Bill
This firewall is an offering from the IBM Cloud Marketplace, so the party that opens the ticket with Fortinet is IBM. My ticket with IBM is CS4391497, but I don’t have the Fortinet ticket number.
Thank you for letting me know. Before you performed the switch-over, did you check anything on the Master device; such as the forwarding-table or certificates?
If possible, please share all the logs you have with me
bhoang@fortinet.com; I am Bill from Fortinet. Thank you
Bill
| User | Count |
|---|---|
| 2702 | |
| 1415 | |
| 810 | |
| 716 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.