Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
heyyo
New Contributor

HA Checksum Recalculate - What happens?

I have an HA firewall which is currently out-of-sync.

Checked the 'out of sync tables' and compared the config on FW-A and FW-B. There is no mismatch.

 

Next step is to work #diagnose sys ha checksum recalculate on both FWs

Will this recalculating command will cause overlay tunnels to failover to secondary unit?

What does it do internally to the firewalls? What is the possible impact to the network?

4 REPLIES 4
Toshi_Esumi
SuperUser
SuperUser

checksum recalculate just recalculates checksum of the config. Nothing else.
But If you don't see any mismatch you shouldn't see "out-of-sync". Should have no effect with recalculation if matching.

Is it what you saw in "get sys ha status"? I meant the out-of-sync.

Did you run "diag sys ha checksum cluster | grep all:" and all were exactly the same?

Toshi

AEK
SuperUser
SuperUser

The mentioned command just recalculates the configuration checksum of the cluster node on which you run it, and doesn't have any impact on the functioning of your FortiGate.

If the out of sync situation is due to checksum calculation and not to configuration itself, when you run it on both cluster nodes to recalculate the checksum the out of sync status is cleared. But if there is a real configuration difference then the out of sync status remains.

This tech tip may help:

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Procedure-for-HA-manual-synchronization/ta...

AEK
AEK
hbac
Staff
Staff

Hi @heyyo

 

Is it a new HA setup? When did the issue start? What was change? 

 

You mentioned that there is no mismatch in the configuration. In that case, I would suggest checking to make sure both units have the same firmware version. 

 

Regards, 

vbandha
Staff
Staff

Hello @heyyo 

Here is a nice guide for resolving HA cluster out of sync. 

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-How-to-troubleshoot-HA-synchronizati...

 

You can check which configuration objects are out of sync and if recalculating checksum doesn't resolve the issue, you can isolate the secondary and reform cluster.

 

If you have any question regarding this, please let me know. 

 

Regards, 

Varun

 

Labels
Top Kudoed Authors