Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
bigkeoni64
Contributor

HA out of sync due to vpn.certficiate.ca

Hello - I have a customer who updated to version 7.2.3 to be clear of the recent SSLVPN vulnerability; however, HA is out of sync and comparing out puts it is showing the vpn.certficiate.ca.

bigkeoni64_0-1671214294803.png

 

This shows to be a bug in an earlier version.

 

Any advice?

 

Thank you

6 REPLIES 6
FredPaul
New Contributor III

Have you tried recalculating the checksums of both HA nodes? That sometimes helps.

-Fredrik
-Fredrik
bigkeoni64

One of the first things I did on both units and no joy.

seshuganesh
Staff
Staff

Hi Team,

 

I understood the issue.

Can you please let me know if its in vdom environment. If its vdom environment in which vdom the HA sync not happening. Is it like in some vdom the certificate present and in some other certificate not present?
If its not in vdom environment, please execute this commnad in both firewalls:

#config vpn certificate ca

#show full

Compare both texts and let us know which certificate is mismatching

If you get to know which certificate is having the issue, please execute these commands and share us the output:

config vpn certificate ca

edit <cert-name>

show full

end

 

Please execute commands in both firewalls and share us the output

 

bigkeoni64

Actually, it seems much simpler - the backup did not take the upgrade for some reason. So right now HA2 is at 7.2.3 and HA1 is at 7.2.2

 

The client will update HA1 after hours. Not really sure why it did not take since it is setup as HA.

 

7.2.3 is really new, maybe a hiccup in the code??

LKA
New Contributor

had the same happen to me on a 101F cluster - 7.0.14

 

For reference:

I got mismatches on system.central-management and certificate.ca - checking those showed absolutely identical. Then I ended up on this post - I ended up logging on to the fgt with lower version and upgraded from there manually again.

lastreaction122
New Contributor


@bigkeoni64 wrote:

Hello - I have a customer who updated to version 7.2.3 to be clear of the recent SSLVPN vulnerability; however, HA is out of sync and comparing out puts crayon it is showing the vpn.certficiate.ca.

bigkeoni64_0-1671214294803.png

 

This shows to be a bug in an earlier version.

 

Any advice?

 

Thank you


HI bigkeoni

I Think This issue may occur from a bug present in earlier versions. Please check the release notes and documentation for version 7.2.3 to identify any known issues related to HA synchronization or the vpn.certficiate.ca discrepancy. Additionally, a thorough review of the HA configuration settings on both devices is advised to ensure they are correctly configured and matching.

Labels
Top Kudoed Authors