Hello guys,
I've 2 600D firewall in HA (Active-Active) mode and we've 3 ISP. Between each ISP connection, there is a switch so that we can get two cable outputs for each firewall.
For temporary reasons, I had changed the ISP2 interface IP to all 0.0.0.0 (and also disconnected the cable) to test something else. And now, when I reassign the public IP to the same interface, it says "This IP is already in use by device 00:09:0f:09:00:15". This is Fortinet MAC address.
What am I missing here?
Details: HA: Active-Active
OS: 5.4.2
VDOM: Yes, 7 No's.
How can I fix this? Please help.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi,
The output message is on web interface or in CLI ?
Is your WAN interface is a VLAN?
Do you have the "sync-config enable" in conf sys ha?
is your cluster in in sync ?
Mac address "00:09:0f:09:00:15" is the mac address of master of slave device ?
That is the output message I get on the Web Interface. On CLI it took the IP, but there was no internet connectivity.
No, its not a VLAN. Its an ISP Ethernet cable coming in, which then connects to an unmanaged switch and then two cables from the unmanaged switch to each firewall.
Yes, sync-config is enabled.
Upon research I found out that the MAC belongs to the ISP1 port. But I checked the config of ISP1 in both GUI and CLI and there is no trace of an IP Conflict between ISP1 and ISP2 ports.
I am not a expert, but maybe the relation between MAC and IP is still in a table, Arp Tabel, NAT table
I rebooted the HA cluster. Shouldn't that clear the NAT/ARP table? Correct me if I'm wrong.
Try rebooting the switch for the IPS's links.
Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com
Yes, done that too.
Have you already check if the IP is set in anywhere in your configuration file ?
config vdom
edit <yourVDOM>
show full | grep <IpYoutryToSet>
When you try to configure in CLI, is your configuration is accepted ? Are you able to do ping?
Do you have more than one IP on your public IP ? if yes, try to configure an unused IP address and :
- exec ping <PublicIpAddressYouTryToConfigure>
- diagnose ip arp list | grep <PublicIpAddressYouTryToConfigure>
-> what is the state of this arp entry?
Maybe you can try to upgrade to 5.4.4.. 5.4.4 has a lot of bug, so I think the 5.4.2 is worst...
Did you verify it? get system arp diagnose sys session list above command can be used with a filter
diagnose sys session filter ?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1710 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.