Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
zexex
Visitor

HA out of sync since 7.2.10

since I've upgraded to 7.2.10 (7.2.9) before, my HA won't sync - since 14 days. Complained about the DNS-table and nothing helped, so I did a factoryreset on the secondary unit and configured the HA params only. Did a reboot and connected only the HA cables. This didn't help either, 30 tables out of sync (why???).

Did another factoryreset and used the same config as on the primary unit and changed only the hostname and the HA priority before that. Restored the config - HA out of sync, this time "only" rule.fmwp and firewall.internet-service-name. Rebooted many times, executed "diag sys ha checksum recalculate" on both units, nothing!

Fortinet, what have you done... Anybody else having such annoying sync-issues or and ideas how to get rid of it?

BTW, "exec update-now" on the secondary unit failed with code -6, so I connected the device to the internet (isolated) and did a "exec update-now". No errors there but still the same result...

3 REPLIES 3
salemneaz
Staff
Staff

Hi,

Would you please run this command "diag debug crashlog read" and check if the HA demon is crashing or not at the Primary Unit. When the HA goes of sync then manually syncing the configuration does.

Article Reference:

--------------------------------

https://community.fortinet.com/t5/FortiGate/Technical-Tip-Procedure-for-HA-manual-synchronization/ta...

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-How-to-troubleshoot-HA-synchronizati...

Salem
Shashwati
Staff
Staff

hello , please try to restart the HA sync processes using following command

 

fnsysctl killall hasync
fnsysctl killall hatalk
 
And run debug to collect HA logs on both Firewalls
 
diag debug reset
diag debug enable
execute ha synchronize stop
diag debug console timestamp enable
diag debug application hasync -1
diag debug application hatalk -1
execute ha synchronize start
 
diag debug reset
diag debug disable   [run his to stop debug]
Toshi_Esumi
SuperUser
SuperUser

I wouldn't waste any more time but just open a ticket and get it looked by TAC.
Did you run "diag debug config-error-log read" on both devices once the first upgrade was done? That likely would have given you a hint what went wrong during the upgrade process.
On the hand, recently I'm experiencing HA issues during/after upgrade with multiple random clusters so TAC created a bug report and DEV is looking into the origin.
That's another reason to open a TAC case.

Toshi

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors