Hello Team,
i have two FGT-400F.
when I configure HA in A-P mode I lose access to mgmt, or rather, I keep losing packets and sometimes I have response but then I lose them again.
HA status seems ok from cli but secondary appears out-of-sync
HA Health Status: OK
Model: FortiGate-400F
Mode: HA A-P
Group: 0
Debug: 0
Cluster Uptime: 0 days 0:43:2
Cluster state change time: 2025-05-05 15:12:06
Primary selected using:
<2025/05/05 15:12:06> FG4H0FTXXXXXXX is selected as the primary because it has the largest value of override priority.
ses_pickup: enable, ses_pickup_delay=disable
override: disable
Configuration Status:
FG4H0FTXXXXXXX (updated 1 seconds ago): in-sync
FG4H0FTYYYYYYY (updated 2 seconds ago): out-of-sync
System Usage stats:
FG4H0FTXXXXXXX (updated 1 seconds ago):
sessions=11, average-cpu-user/nice/system/idle=0%/0%/1%/98%, memory=20%
FG4H0FTYYYYYYY (updated 2 seconds ago):
sessions=0, average-cpu-user/nice/system/idle=0%/0%/0%/99%, memory=19%
HBDEV stats:
FG4H0FTXXXXXXX (updated 1 seconds ago):
ha: physical/1000auto, up, rx-bytes/packets/dropped/errors=8544725/20866/0/0, tx=9549211/22088/0/0
FG4H0FT924904723(updated 2 seconds ago):
ha: physical/1000auto, up, rx-bytes/packets/dropped/errors=9547147/22081/0/0, tx=8541769/20862/0/0
Primary : FGT-1, FG4H0FT924904724, HA cluster index = 0
Secondary : FGT-2, FG4H0FT924904723, HA cluster index = 1
number of vcluster: 1
vcluster 1: work 169.254.0.1
Primary: FG4H0FTXXXXXXX , HA operating index = 0
Secondary: FG4H0FTYYYYYYY , HA operating index = 1
Do you have any suggestions?
Thanks for the support
BR
Solved! Go to Solution.
Hello,
unconfigure HA then execute factoryreset on the secondary member and then reconfigure HA and all work as expected.
Thanks to all for the support
BR
Then share us the 500E's "config system ha" and "config system interface -> edit mgmt".
Toshi
Tomorrow morning will be possible for me.
Thanks
Unless the behavior is changed from your FGT 500E firmware version to your FGT 400F firmware version.
But for more recent firmware versions, such as 6.4, 7.x, the behavior is always to sync the interface with the "dedicated-to management" setting unless it is used in HA dedicated management interface settings.
Hello @Toshi_Esumi,
following configuration of mgmt interface and ha for fgt500e
edit "mgmt"
set vdom "root"
set ip x.x.x.x 255.255.255.0
set allowaccess ping https ssh snmp http fgfm
set type physical
set dedicated-to management
set snmp-index 2
next
config system ha
set group-name "xxxxx"
set mode a-p
set password xxxxxxx
set hbdev "ha" 0
set session-pickup enable
set override enable
set priority 200
thanks
br
What is the firmware version for your FGT 500E?
6.4.16 (M) that is the same version of fgt 400F
Thanks
Hello,
I have now upgraded the 400F firmware to 7.2.7 (M).
Now I only enabled HA on one node, after enabling it with this conf:
config system ha
set group-name "ClusterFGT"
set mode a-p
set password XXXXXXXXXXX
set hbdev "ha" 0
set session-pickup enable
set override disable
set priority 150
end
I lose access to management (it has been 20/25 minutes) . Out of 231 icmp packets to mgmt only 17 responded to me and at different times.
I have the MGMT with the parameter “set dedicated-to management”.
Please help me
Thanks again
Hello,
the problem is gorup-id. Now i configure group-id 1 and the HA is forme correctly but the second membre is out-of-sync for different system.npu checksum. How do I fix it?
Thnaks for the support
Hello,
unconfigure HA then execute factoryreset on the secondary member and then reconfigure HA and all work as expected.
Thanks to all for the support
BR
ok thanks. the mgmt interface have dedicated-to-management enable by default. i don t change it
User | Count |
---|---|
2554 | |
1356 | |
795 | |
647 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.