Hey guys.
I have 2 60F v 7.2.11 and I'm monitoring via Zabbix 6.0.4. We use the oficial template to fortigate and cluster. I'm having an issue with an HA cluster where Zabbix keeps alerting from time to time that an HA member is down, when accessing the firewall. Everything is fine and synchronized. I've already restarted the service, rebooted the firewalls, and still the HA alarm keeps triggering.
The same template is used for other firewalls.
Why 7.2 and not something newer?
What does Zabbix say? This sounds like a questions for them.
Hi
Probably the template is for other versions and doesn't work well with 7.2.11, or probably there is some wrong output from the FortiGate.
To investigate more you need to find which SNMP query is getting this wrong info, or which SNMP trap or which Syslog message. I didn't use Zabbix since years but I remember we can find exactly which one is causing the alarm.
After you find it you should discover what's wrong with the template or maybe you will find some output that doesn't match what is expected by the template.
You need to be good enough in Zabbix to troubleshoot the issue.
Created on ‎12-11-2025 06:17 AM Edited on ‎12-11-2025 06:18 AM
Hi, thaks for your answer,
I forgot to say, but the fortigate cluster is behind three different routers of different internet links, and we use the same template for around 40 fortigates in the same firmware, just different hardwares. Would the routers interfeer? They don't have restriction policies , all simple.
Then here are some first checks:
1- On Zabbix use "tcpdump host fgt-ip" to see if ther are always replies from FortiGate when Zabbix sends queries to it.
2- On FGT use the following command to check if the communication with Zabbix is coming from the same WAN interface as the one from which the response is returning.
diag sniffer packet any "host zabbix-ip" 4
The output should show only one single WAN interface for in and out traffic, otherwise there will be confusion for Zabbix.
3- As suggested before, to investigate more you need to find (using Zabbix tools) which SNMP query is getting this wrong info, or which SNMP trap or which Syslog message is getting this wrong information. This will provide more info on what's going on.
Hope it helps.
| User | Count |
|---|---|
| 2841 | |
| 1436 | |
| 812 | |
| 800 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.