Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
mbrodzin
New Contributor

Fortigate HA - two units are not seeing each other

Hi All,

 

Lately i was setting up A-P HA with FG60F (same version, same HW version etc). After connecting HA port, they were up, but unit 1 didn't see unit 2 and vice versa.

 

Has anyone had a similar case?

 

Regards

Mbrodzin

 

4 REPLIES 4
Walter_
New Contributor

Walter
mbrodzin

Hi Walter_,

 

Not the same issue. Your HA was setup, but not synchronizing. My two units don't see each other after connecting the HA ports.

 

Regards

Mbrodzin

dingjerry_FTNT

Hi @mbrodzin ,

 

First of all, you need to capture sniffer packets on your HA heartbeat interface(s) to see whether there are any packets or not.

Regards,

Jerry
Walter_
New Contributor

Isolate the Secondary FortiGate and rebuild the HA config.

If the cluster is still not in sync, isolate the Secondary FortiGate from the cluster. This process will require physical access to the FortiGates.

 

Important: before starting this process, take a backup of the FortiGate configuration.

 

Step 1: Disconnect all network cables from the secondary unit except for the heartbeat cables.

Step 2: Disconnect the heartbeat cable. This will disconnect the secondary FortiGate from the network.

Step 3: Connect to the secondary FortiGate using the console and perform a factory reset:

 

execute factoryreset

 

See Technical Tip: How to reset a FortiGate with the default factory settings/without losing management ... for detailed instructions.

 

Step 4: After the FortiGate comes back online, login again and configure the HA settings. Make sure to keep the priority low for the secondary FortiGate in HA settings (lower than the primary FortiGate).

Step 5: After that is configured, connect the HA cable to the heartbeat interface of the secondary. Do not connect any other cables at this time.

The secondary FortiGate should show up in the HA. If the secondary FortiGate does not show up in HA settings, do not proceed to the next step.

Step 6: The secondary FortiGate should have joined the secondary role. After verifying that this has happened (using GUI or CLI of primary), connect all of the other network cables to the secondary FortiGate as per the previous setup.

Step 7: Verify the status of the configuration sync from Primary FortiGate - it should show that both Primary and secondary units are in sync.

Walter
Walter
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors