I have fortigate firewall acting as wifi controller as well, my issue here is that when I perform manual HA failover or upgrade the firewall, switchover is not seamless and it take at least 5 minutes to switch services for secondary unit. configuration is active passive
Dear @Lucky-Cement
Please verify that the `session-pickup` is enabled in the HA configuration. This ensures that existing sessions are synced and persist upon failover.
- Confirm that the primary FortiGate has a higher priority than the secondary.
- Ensure that the `override` setting is configured correctly to allow preemptive failover and fallback.
- Check the heartbeat interface connections between the primary and secondary units to ensure they are stable and functioning correctly.
- Review the system logs for any errors or warnings that might indicate issues during the failover process.
- Perform a manual failover test to observe the behaviour and identify any specific delays or issues.
Best regards,
Erlin
hi,
- session-pickup is enabled
- priority is set right (higher for primary)
- kindly explain the "override" settings
- heartbeat interface is working correctly
- warning that I saw is system rebooted, what else to find?
- have done it with same result.
When configuring FortiGate High Availability (HA) settings, the "override" feature plays a crucial role in determining the primary unit within an HA cluster.
Here's an explanation of the "override" settings and additional steps you can take given the warning you encountered:
1. Override Settings:
- Override Disabled: When the override feature is disabled, the primary unit selection is based on the robustness of the system rather than the configured priority.
This means that even if a unit has a higher priority, it may not become the primary if another unit is deemed more robust.
- Override Enabled: When enabled, the unit with the highest priority will always be selected as the primary, regardless of the system's robustness.
2. System Reboot Warning:
- If you received a warning that the system rebooted, it is essential to investigate the cause of the reboot. Here are some steps you can take:
- Check System Logs: Review the system logs for any error messages or events leading up to the reboot.
- Monitor Resource Usage: Ensure that CPU and memory usage are within normal limits, as resource exhaustion can lead to reboots.
- Inspect Hardware: Verify that there are no hardware issues, such as faulty components or overheating.
- Check HA Events Logs.
Best regards,
Erlin
May I know what the Fortigate model and its version are ?
override is disabled as I have configured priorities on firewalls, I have enabled/disabled session pickup but result is same, firewall is 201F firmware is 7.4.7
no any hardware or software issues or errors
Thanks for your infor @Lucky-Cement
I will conduct a test.
any update on the test?
Hi Lucky,
In my testing, the failover completes within seconds (under 30 seconds).
If you don't mind, could you please share your configuration with me via my official email thiep@fortinet.com? I'd like to try it out on my end.
Regards,
Harry
Have you done some debugging or tcpdumps as maybe there is ha heartbeats lost etc?
How to troubleshoot HA 'Heartbeat pac... - Fortinet Community
Also if GARP is lost because there are switches or other network devices blocking this could be an issue.
How gratuitous ARP behaves on FGCP HA fai... - Fortinet Community
User | Count |
---|---|
2561 | |
1357 | |
796 | |
650 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.