Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
letsdothis
New Contributor

FortiGate in HA (A-P) does not failover everything

I have FortiGates in HA (A-P) but recently when a failover happened, I noticed on the the vdom didnt failover also noticed when looking at the route monitoring on the secondary FG that the connected routes were deleted. only two or three were left.  Not sure what the reason is for this because the FGs are in sync.

#fortigate #ha #failover

1 REPLY 1
akileshc
Staff
Staff

Hi,

 

Based on your description, it seems that the FortiGates in Active-Passive HA configuration experienced a failover issue where not all VDOMs transitioned properly, and some connected routes were missing on the secondary firewall (now the new master).

 

If yes, it’s recommended to verify that all VDOMs are correctly configured to failover during the HA process and the cluster nodes are in sync before triggering the failover. Importantly, each VDOM should be synchronized across both units, as any misconfigurations or checksum mismatches can result in one or more VDOMs remaining inactive during failover. Additionally, a newly elected master in an HA cluster may have experienced a link monitor or interface failure, leading to the removal of connected routes.

 

However, collecting the information such as ha status, routing-table output, and the debug output for process hasync & hatalk would help in determining the actual cause for the behavior you noticed. 

 

 

Akilesh
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors