Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
agrammenos
New Contributor

Fortimanager HA Operation - Request for Comments

After a case of installation of 2 fortimanagers in HA mode I ve realized that when Primary Node is lost or shutdown Secondary node is not automatically promotes as Primary.

So I ve created a lab with 2 Fortimanagers and 1 Fortigate in order to explore this operation and how to recover from such situation.

 

Following my documented experience which I request for your Comments in case somethng is not well understood documented or wrong.

 

>>>>>>>>>

Info: In HA architecrure Primary node pushes changes dynamically to Secondary and HA cluster heartbeat conectivity test is executed every 5 sec (if default). So in case of loss of Primary Node you can assume that secondary node is up to date with latest config.

1. In case of permanent loss of Primary node you need to: Warning: Procedure does not apply for temporary loss of Primary Node (like reboot, power failure). a. Repurpose Secondary node to Standalone from GUI or CLI. Info: if you just repurpose Secondary node to Primary (with Primary in offline mode), management of dependent Fortigates cannot be accomplished. b. Wait a few seconds to reestablish status of fortigates.

c. Manage Fortigates. 2. In case of sceduled maintenance windows where Primary node must be set offline:

a. Switch roles Between Primary and secondary node. Info: This can be aranged with HA Members both online from GUI/CLI

b. wait a few seconds to reestablish status of fortigates.

c. Shutdown (new) Secondary Node (previous master). 

d. Manage Fortigates from (new) Master.

 

3. In case of permanent loss of Primary and Secondary Nodes, dependent Fortigates can be managed directly without Warning of the aditional option menu to connect Readonly/readwrite. Warning: In this case if you manage to have operational a Primary Fortimanager, then all aditional changes made directly to fortigate will be undo upon next Policy Install from Fortimanager.

0 REPLIES 0
Labels
Top Kudoed Authors