Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
achin
New Contributor

Fortigate upgrade with HA unsynchronized

I have two unsynchronized fortigate 200f devices (v7.2.5) hooked up to HA.
After the last update the checksums got so bad that the only path recommended by support was to configure the slave device from scratch. Recalculating the checksums manually didn't do anything.

I concluded that I would hold off until the new firmware was released, hoping that after uploading v7.2.6 the devices would sync up again.

Has anyone used this solution successfully? Should I now start the upgrade with the master or slave?

https://19216811.cam/ https://1921681001.id/
3 REPLIES 3
xshkurti
Staff
Staff

@achin 
If you try to upgrade while fortigates are not in synch, your upgrade most probably will stuck and not go forward.

So the best case is to disconnect secondary unit, upgrade both members separately, factory reset secondary device, and configure cluster settings, then connect HA port cables , wait for it to synch and then connect traffic carrying ports.

Toshi_Esumi
SuperUser
SuperUser

7.2.6 has been out since two weeks ago. But if two many parts of configuration is unsyncable due to conflicts, most unlikely upgrading both units wouldn't help match. I would just isolate the secondary, factory reset, configure HA, then re-reconnect heartbeat connection to the primary to let it sync, which keep watching at the progress of syncing at both primary and secondary console ports.

 

Toshi

Labels
Top Kudoed Authors