Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
dbeitler
New Contributor III

HA a/p on new 601E units not working. Not seeing each other.

Have two new 601E Fortigate units. Running identical firmware.

Each think they're the only one.

 

HA port is green on both.  If I reboot the "secondary" the "primary" sees the link drop.

Primary is set to priority 200, secondary is left at default.

Reset password just to be sure.  Group name is correct on both units.

Secondary has been factory reset, and only the hostname and  HA config settings added.

Both units have been registered, although the secondary cannot talk to FG at the moment since the public link has not been reconfigured, but is connected.

The "inside" interface is not yet connected..

The HA interfaces are directly connected.  No switch or hub between.

 

They just don't seem to see each other.  Ran several of the suggested diag commands, and don't see anything obvious.

 

1 Solution
pgautam

Hi @dbeitler 


Thank you for sharing the error log.

 

Please check if you are observing any discrepancies in the FIPS setting.

You can check the  setting status from the below command output

get system status

 

If you observe any difference in the cluster member then make the setting the same.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-FIPS-CC-mode/ta-p/196629

 


Regards
Priyanka


- Have you found a solution? Then give your helper a "Kudos" and mark the solution

View solution in original post

4 REPLIES 4
pgautam
Staff
Staff

Hi @dbeitler

 

Thank you for posting your query.

 

As per the description, the FGT cluster is in a split-brain scenario.

 

A split-brain scenario is usually caused by a complete loss of the heartbeat link or links. This can be a physical connectivity issue, or less commonly, something blocking the heartbeat packets between the HA members. Another cause is congestion and latency in the heartbeat links that exceed the heartbeat lost intervals and thresholds.

 

To resolve a split-brain scenario:

>> Be physically on-site with the FortiGates (recommended). If this is not possible, connect to the FortiGates using console access.
>> Identify the heartbeat ports, and verify that they are physically connected and up.
>> Verify that heartbeat packets are being sent and received on the heartbeat ports.
>> Verify that the HA configurations match between the HA members. The HA mode, group-name, group-id, and password settings should be the same. Different
>> group-id values will result in different virtual MAC addresses, which might not cause a MAC conflict. However, an IP conflict can still occur.
>> If everything seems to be in working order, run get system ha status to verify that HA has formed successfully.


To avoid a split-brain scenario:

>> In a two-member HA configuration, use back-to-back links for the heartbeat interface instead of connecting through a switch.
>> Use redundant HA heartbeat interfaces.


You can use the debug commands to check heartbeat communication and sync status.

 

Collect the output of the below command from both the unit:-

 

diagnose debug reset
diagnose debug console timestamp enable
diagnose debug application hatalk -1
diagnose debug application hasync -1
diagnose debug enable


wait for a couple of minutes, and then disable the logs by executing

diagnose debug disable

 


Regards
Priyanka


- Have you found a solution? Then give your helper a "Kudos" and mark the solution

dbeitler
New Contributor III

The diagnose commands showed the following:

"enc/auth mismatch: hdr_enc/auth=1/1, my_enc/auth=0/0"

and lists the serial # of the opposite unit.  Resetting the HA password did not change the result.

pgautam

Hi @dbeitler 


Thank you for sharing the error log.

 

Please check if you are observing any discrepancies in the FIPS setting.

You can check the  setting status from the below command output

get system status

 

If you observe any difference in the cluster member then make the setting the same.

https://community.fortinet.com/t5/FortiGate/Technical-Tip-How-to-enable-FIPS-CC-mode/ta-p/196629

 


Regards
Priyanka


- Have you found a solution? Then give your helper a "Kudos" and mark the solution

dbeitler
New Contributor III

D'oh

Yes.  I had enabled both in the beginning for fips-cc mode.  The factory reset removed it from the secondary.  Too many things going on.  

Thanks for the light.

Labels
Top Kudoed Authors