Hi Gents,
we set up 2 fortigate 601E running in HA (A-P) mode, i.e FW01-Primary, FW02-Secondary. the system is configured in transparent mode, with one uplink and one downlink port. Both ports are set as monitor ports in HA settings. I expected in the scenario when hardware fault or link fault, failover will be triggered and session will be pickup automatically. We run multiple tests for HA features.
Observation #1: #When we reboot the FW01, FW02 becomes the primary and pickup the sessions. However, when FW01 was bootup, FW01 was taken over as primary but the sessions were lost. As long as I reboot the FW02, the sessions can then be recovered
Observation #2: the uplink ports (connected to a switch) is one of the monitor port for failover. When I shutdown the uplink port at switch side, the failover does work to FW02 as primary. However, when I turn on the uplink port, FW01 resume to primary role, while sessions are lost. I can only shutdown the 2nd uplink port connecting to FW02 or reboot FW02 to resume all the sessions.
Does anyone have suggestions to me ?
Created on 07-25-2022 07:05 PM
Hello @ricyeunghk2003 ,
Thank you for using the Community Forum.
I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Regards,
Hi @ricyeunghk2003 ,
Observation 1: This can be expected behavior. On normal scenario, Unit1 and Unit2 is UP. session pickup is sync to Unit2. When Unit1 is loss, the session is loss. Please check if you enable session pickup.
Observation 2: Related to Observation 1.
Basically, transition between Unit1 to Unit2, mostly no issue because all session is catch by Unit2 while Unit1 is UP.
When Unit2 transition to Unit1, you may have session issue because, some session cannot be sync due to session is created before the Unit1 is up. This mostly happened to HTTPS traffic.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1778 | |
1116 | |
767 | |
447 | |
242 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.