I am not sure if this is normal behaviour or a problem?
Our Fortiproxy cluster loses the sync approx. every 10 minutes, then it is out of sync for 1-2 minutes, then it syncs again. I can see it in GUI, on the CLI and also with SNMP.
It is active-passive HA with unicast heartbeat on explicit HA-interfaces in VLAN which is only used for this.
I've already rebootet both devices (VM64 v7.4.2 build0577).
Switchover worked fine.
It is not a network issue!
When I captured the traffic I've not only seen UDP-traffic between the peers, but also TCP on ports 703 and 700.
703 is mentioned in the Fortiproxy port table, but 700 is not in the list (seems to be harelay).
https://docs.fortinet.com/document/fortiproxy/7.4.0/fortiproxy-ports/758533/incoming-ports
Any tipps?
Thanks.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
There is an issue fixed in FortiOS 7.4.4 that "may" be related to your case.
976160 | In a FortiGate HA, the unit periodically produces a warning message for a missing sync file. |
You can check the HA events to see if this is the same case as yours.
Or you can over the secondary unit under menu System > HA, to see what is not synchronized as the issue occurs.
You can also follow this guide for further troubleshooting (it is for FG but also valid for FortiProxy).
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-How-to-troubleshoot-HA-synchronizati...
Hope it helps.
Thanks for the hint.
This might be the solution.
I'll check.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1634 | |
1063 | |
751 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.