Hi Team,
I have configured In-band management access for taking the access of both Pri and Sec devices from different network but I am only able to take access of primary device not secondary.
I had checked in the sniffer, traffic was coming from the management interface but it was returning back to the source.
Kindly suggest.
So, you did not fix it but you changed your mind and moved from in-line to out-of-band management, right? Just asking, because I am facing same issue. I can not manage to get passive cluster member access. Thanks.
In-line we can't reserve the port that's why used OOB.
My requirement was to have both firewall access independently. So, I just pass the traffic via firewall and re-route the traffic from core switch to the mgmt port. As we know after reserving the mgmt port we can't assign the port in the policy.
External Network ----> FortiGate -----> Core Switch -----> FortiGate Mgmt port
FortiGate is same in the flow. Hope you understood.
I got it thank you. I am exactly in the same situation. So I am trying to have independent access to each node without crossing the FW to manage it (like you did with OOB). But looks like in line solution does not work...
Hmm.. This is only way to achieve this.
| User | Count | 
|---|---|
| 2727 | |
| 1417 | |
| 810 | |
| 738 | |
| 455 | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.