Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
luca1994
Contributor

Lost MGMT after configure HA A-P

Hello Team,

 

i have two FGT-400F.

when I configure HA in A-P mode I lose access to mgmt, or rather, I keep losing packets and sometimes I have response but then I lose them again.

HA status seems ok from cli but secondary appears out-of-sync

 

HA Health Status: OK
Model: FortiGate-400F
Mode: HA A-P
Group: 0
Debug: 0
Cluster Uptime: 0 days 0:43:2
Cluster state change time: 2025-05-05 15:12:06
Primary selected using:
<2025/05/05 15:12:06> FG4H0FTXXXXXXX is selected as the primary because it has the largest value of override priority.
ses_pickup: enable, ses_pickup_delay=disable
override: disable
Configuration Status:
FG4H0FTXXXXXXX (updated 1 seconds ago): in-sync
FG4H0FTYYYYYYY (updated 2 seconds ago): out-of-sync
System Usage stats:
FG4H0FTXXXXXXX (updated 1 seconds ago):
sessions=11, average-cpu-user/nice/system/idle=0%/0%/1%/98%, memory=20%
FG4H0FTYYYYYYY (updated 2 seconds ago):
sessions=0, average-cpu-user/nice/system/idle=0%/0%/0%/99%, memory=19%
HBDEV stats:
FG4H0FTXXXXXXX (updated 1 seconds ago):
ha: physical/1000auto, up, rx-bytes/packets/dropped/errors=8544725/20866/0/0, tx=9549211/22088/0/0
FG4H0FT924904723(updated 2 seconds ago):
ha: physical/1000auto, up, rx-bytes/packets/dropped/errors=9547147/22081/0/0, tx=8541769/20862/0/0
Primary : FGT-1, FG4H0FT924904724, HA cluster index = 0
Secondary : FGT-2, FG4H0FT924904723, HA cluster index = 1
number of vcluster: 1
vcluster 1: work 169.254.0.1
Primary: FG4H0FTXXXXXXX , HA operating index = 0
Secondary: FG4H0FTYYYYYYY , HA operating index = 1

 

Do you have any suggestions?

Thanks for the support

BR

1 Solution
luca1994

Hello,

 

unconfigure HA then execute factoryreset on the secondary member and then reconfigure HA and all work as expected.

 

Thanks to all for the support

BR

View solution in original post

29 REPLIES 29
Toshi_Esumi

Then share us the 500E's "config system ha" and "config system interface -> edit mgmt".

Toshi

luca1994

Tomorrow morning will be possible for me. 

Thanks

dingjerry_FTNT

Unless the behavior is changed from your FGT 500E firmware version to your FGT 400F firmware version.

 

But for more recent firmware versions, such as 6.4, 7.x, the behavior is always to sync the interface with the "dedicated-to management" setting unless it is used in HA dedicated management interface settings. 

 

 

Regards,

Jerry
luca1994

Hello @Toshi_Esumi,

 

following configuration of mgmt interface and ha for fgt500e

 

edit "mgmt"
set vdom "root"
set ip x.x.x.x 255.255.255.0
set allowaccess ping https ssh snmp http fgfm
set type physical
set dedicated-to management
set snmp-index 2

next

 

config system ha
set group-name "xxxxx"
set mode a-p
set password xxxxxxx
set hbdev "ha" 0
set session-pickup enable
set override enable
set priority 200

 

thanks

br

dingjerry_FTNT

What is the firmware version for your FGT 500E?

Regards,

Jerry
luca1994

6.4.16 (M) that is the same version of fgt 400F

 

Thanks

luca1994

Hello,

 

I have now upgraded the 400F firmware to 7.2.7 (M).

 

Now I only enabled HA on one node, after enabling it with this conf:

config system ha
set group-name "ClusterFGT"
set mode a-p
set password XXXXXXXXXXX
set hbdev "ha" 0
set session-pickup enable
set override disable
set priority 150
end

 

I lose access to management (it has been 20/25 minutes) . Out of 231 icmp packets to mgmt only 17 responded to me and at different times.

I have the MGMT with the parameter “set dedicated-to management”.

 

Please help me

Thanks again

luca1994

Hello,

 the problem is gorup-id. Now i configure group-id 1 and the HA is forme correctly but the second membre is out-of-sync for different system.npu checksum. How do I fix it?

 

Thnaks for the support

 

luca1994

Hello,

 

unconfigure HA then execute factoryreset on the secondary member and then reconfigure HA and all work as expected.

 

Thanks to all for the support

BR

luca1994
Contributor

ok thanks. the mgmt interface have dedicated-to-management enable by default. i don t change it

 

Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors