The primary firewall was restarted, causing the secondary unit to become the primary. However, it is not syncing with the primary, and both HA cables are active.
Under menu System > HA, put the mouse cursor on the not-synced node, you will see which config section is causing the issue.
Then compare this section between the two nodes, correct it, then run the following:
diagnose sys ha checksum recalculate
This is the KB for the troubleshooting process.
https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-How-to-troubleshoot-HA-synchronizati...
Toshi
Hi @RHFLMPLS ,
When you are talking about an HA issue, it's better to use Unit A and Unit B for the HA cluster members.
For example, your issue can be rephrased as below:
===============================
I have HA cluster, A was Primary and B was Secondary. After A was restarted, B is Primary now. However, A is not syncing with the B device and both HA cables are active.
===============================
Usually, FGT HA needs to take time to sync up. If you still see them not in sync, please use the methods provided by @Toshi_Esumi and @AEK to collect more info.
User | Count |
---|---|
2551 | |
1356 | |
795 | |
646 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.