Hello,
We experience an issue where we have 2 Fortigate clusters in the same datacenter.
We have an Fortigate 100F cluster in Active-Passive with an IPSEC tunnel towards an Fortigate 60F cluster in Active-Passive.
Both are running the 6.4.9 firmware.
When the 100F cluster is running on the primary, traffic is passing along the IPSEC tunnel fine.
As soon as I failover the 100F cluster to the passive firewall, traffic stops passing (in both directions) along the tunnel. When I failover the 60F firewalls, this issue does NOT occur, and traffic keeps on passing.
The HA setup is the same, except for the 100F cluster which runs VDOM's (the IPSEC tunnel is NOT in the root VDOM) and the 60F cluster does NOT.
Anyone has seen this before and has the solution?
This issue does NOT occur when we failover the 60F cluster.
Did you try to enable "session pickup" in HA config?
Well I'm not certain this will fix it but it's worth a try.
Hi,
Yes, this feature has been enabled.
I also have enabled the set ha-sync-esp-seqno enable feature on the 100F cluster.
The strange part is: it only breaks when failing over the 100F cluster.
When failing over the 60F cluster everything keeps working fine.
I have also tried flushing the VPN tunnel after the failover, that doesn't help either.
Regards,
User | Count |
---|---|
2152 | |
1189 | |
770 | |
451 | |
347 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.