Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
silversurfer
New Contributor

HA broken - how do i fix?

Hi all, My HA broke, when i plug in firewall 1 lan both firewalls goes offline (non functional). From the support tells me to do a factory reset and then set group-id etc. Did a factory reset and of course i can' t connect to firewall 1 (i' m off site). Is there a way to connect to it, true firewall 2 (cli)? I have only WAN and sync connected between the firewalls and i don' t see any ip on sync-inteface. Is the console the only way now (on site)? How do i recreate the HA easiest and best way? thx
13 REPLIES 13
silversurfer
New Contributor

Hi, Thx for the tip. Did that acctually but now i only have a policy left (internal interface = switch), if i delete that i cant access the switch anymore via https?
Paul_Dean

Not sure what you mean exactly. I deleted all of the policies on a default 200A and was still able to access the FGT gui via https. It does remove the IP address from the interface once you switch from switch to interface so it might cut you off. If you have access to the FGT via a different interface with ssh you could run the commands in the CLI. config system global set internal-switch-mode interface end Otherwise, download the config. Make the changes you need by hand including any ip configuration and upload it again. It might be enough to rename all instances of " internal" to " internal1" and enable interface mode. I' ve not tested that.
NSE4
NSE4
silversurfer
New Contributor

Hi, Got it working. Had to change port, guessing some vlan (trunk) was the problem. So, now i can resync this fw to master via config - HA, just put it on active-passive, same password, other priority, Session-pickup, same port. mån and heartbeat interface - press ok?
nerk
New Contributor

I have a Fortigate 3600 running v4.0,build0513,120130 (MR3 Patch 5) I have an application that is timing out at 1 hour and all indications point to the firewall timing out the TCP session. We think it' s using TCP 2025 1. Is there a default TTL for all TCP sessions and if so how do I check what it currently is. 2. If I' d like to change the TTL for just TCP 2025 port, what would the commands be to do so and also the commands on how to change it and how to undo it. 3. Would like to know if there is a maximum TTL time in minutes or hours I can set for this port.
Jim
Jim
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors