Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
jihen
New Contributor

FortiWeb HA Synchronization Issue Between Master and Secondary


Hello everyone,

I currently have two FortiWeb VMs configured in an HA cluster (Active-Passive mode). However, I’m facing an issue during the HA setup. When I enable HA, the master node completely overwrites the configuration of the secondary node, causing it to lose its initial settings. In addition, after the negotiation process between the two FortiWebs, the cluster does not become active — both devices remain separate and do not synchronize properly. I would like to know how to prevent the master from overwriting the configuration of the secondary during synchronization, and how to fix the issue that prevents the two FortiWebs from forming a functional cluster.

Thank you in advance for your help and advice.

1 REPLY 1
AEK
SuperUser
SuperUser

Hi Jihen

  1. Regarding the first part of your post, in active-passive HA mode, when you say "the master node completely overwrites the configuration of the secondary node", I confirm this how it is supposed to work.
  2. Regarding the second part, to synchronize properly you need:
    • A valid license for both cluster members
    • The cluster members must have the same number of ports and are configured with the same amount of memory and vCPUs
    • On the heartbeat interfaces you must enable promiscuous mode and MAC address changes
    • On the traffic interfaces you must enable Promiscuous mode, MAC address changes and Forged transmits

Ref1: https://docs.fortinet.com/document/fortiweb/7.6.5/administration-guide/182034
Ref2: https://help.fortinet.com/fweb/583/Content/FortiWeb/fortiweb-admin/ha.htm

Hope it helps.

AEK
AEK
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors