Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Lucky-Cement
New Contributor

Fortigate firewall HA switchover causing delay

I have fortigate firewall acting as wifi controller as well, my issue here is that when I perform manual HA failover or upgrade the firewall, switchover is not seamless and it take at least 5 minutes to switch services for secondary unit. configuration is active passive

12 REPLIES 12
esalija
Staff
Staff

Dear @Lucky-Cement 

Please verify that the `session-pickup` is enabled in the HA configuration. This ensures that existing sessions are synced and persist upon failover.
- Confirm that the primary FortiGate has a higher priority than the secondary.
- Ensure that the `override` setting is configured correctly to allow preemptive failover and fallback.
- Check the heartbeat interface connections between the primary and secondary units to ensure they are stable and functioning correctly.
- Review the system logs for any errors or warnings that might indicate issues during the failover process.
- Perform a manual failover test to observe the behaviour and identify any specific delays or issues.

 

Best regards,

Erlin

Lucky-Cement
New Contributor

hi,

 

- session-pickup is enabled

- priority is set right (higher for primary)

- kindly explain the "override" settings

- heartbeat interface is working correctly

- warning that I saw is system rebooted, what else to find?

- have done it with same result. 

esalija

HI @Lucky-Cement 

 

When configuring FortiGate High Availability (HA) settings, the "override" feature plays a crucial role in determining the primary unit within an HA cluster.
Here's an explanation of the "override" settings and additional steps you can take given the warning you encountered:

1. Override Settings:
- Override Disabled: When the override feature is disabled, the primary unit selection is based on the robustness of the system rather than the configured priority.
This means that even if a unit has a higher priority, it may not become the primary if another unit is deemed more robust.
- Override Enabled: When enabled, the unit with the highest priority will always be selected as the primary, regardless of the system's robustness.

2. System Reboot Warning:
- If you received a warning that the system rebooted, it is essential to investigate the cause of the reboot. Here are some steps you can take:
- Check System Logs: Review the system logs for any error messages or events leading up to the reboot.
- Monitor Resource Usage: Ensure that CPU and memory usage are within normal limits, as resource exhaustion can lead to reboots.
- Inspect Hardware: Verify that there are no hardware issues, such as faulty components or overheating.
- Check HA Events Logs.

Best regards,
Erlin

HarryTran
Staff
Staff

May I know what the Fortigate model and its version are ?

Lucky-Cement
New Contributor

override is disabled as I have configured priorities on firewalls, I have enabled/disabled session pickup but result is same, firewall is 201F firmware is 7.4.7

no any hardware or software issues or errors

HarryTran

Thanks for your infor @Lucky-Cement 
I will conduct a test.

Lucky-Cement

any update on the test?

 

HarryTran

Hi Lucky,

 

In my testing, the failover completes within seconds (under 30 seconds).
If you don't mind, could you please share your configuration with me via my official email thiep@fortinet.com? I'd like to try it out on my end.

Regards,
Harry

filiaks1
Contributor II

Have you done some debugging or tcpdumps as maybe there is ha heartbeats lost etc?

 

How to troubleshoot HA 'Heartbeat pac... - Fortinet Community

 

 

Also if GARP is lost because there are switches or other network devices blocking this could be an issue.

 

How gratuitous ARP behaves on FGCP HA fai... - Fortinet Community

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors