Hi
I lost access to the web ui of the fortigate fw after changing the ha settings from active-passive to standalone. As soon as i selected standlone and clicked OK, fw starts buffering for sometime and then i lost the web ui and ssh access.
then wento inside DC and connected laptop to mgmt interface in same subnet still web ui inaccessible, via console am able to access the cli and found mgmt interface ip was not present. I set the ip address again and tried accessing which failed. I took a reload of the device but of no use.
Now what can i do further to take the web ui access?
Hi Zayd
When you configure mgmt port, ensure you enter the following:
set allowaccess http https ping ssh
I did that bro. But of no use
i tried configuring data port on a diff network and tried to connect that as well to the laptop but of no help
I want to know what happens when we change the ha config from a-p to standalone?
why the mgmt ip lost?
running v7.4.2
Created on ‎05-17-2025 10:34 AM Edited on ‎05-17-2025 10:36 AM
If you change the HA to standalone while you're in the primary unit, the secondary device has suddenly lost communication to the primary and takes the primary role. As the result, all IPs on the same network would conflict and compete each other between them when any packets come from outside.
So when you separate the HA pairing, like changing them to standalone, you have to isolate the secondary from your network first, like disabling all in/out interfaces to/from it at the switches connected them together.
Or, if you do that, you didn't have to change the primary's mode to standalone at the first place. Probably running only with the primary was the reason you made the mode change, I assume.
Toshi
Thanks for the response.
in my case my passive was recently rmaed, to put the new unit into cluster there were issues with ha sync, so to make the ha settings again on both units we tried to redo the ha settings on primary by changing it to standalone and was planning to make a-p again. In the middle of all this, the new unit was just powered on with no cables connected.
hence as soon as i shifted the primary ha to standalone its mgmt access lost and the ip add on the mgmt also vanished.
so this is the history.
hope you all got it.
so when contacted tac they told reboot and check it it doesnt come back they flash format and put the backup config again etc.
this i want to avoid becoz without understanding why we lost mgmt access due to ha settings change is something fortinet tac is unable to answer atleast yesterday.
Created on ‎05-17-2025 03:26 PM Edited on ‎05-17-2025 03:35 PM
Not sure what the model your FGT is. But if that's a model that has a physical "MGMT" port and you don't see "mgmt" interface under "config sys int", the "format & reload image" would be the only hope you might get it back as TAC said. Because it's a physical port, whatever you do config-wise, it should never go away.
And, I don't remember when last time I had to change the HA mode to standalone. We have multiple HA clusters in production and had to replace a member in cluster for RMA or reformat it multiple times last 10 years or more. We always keep the a-p mode once the cluster was formed, and manipulate the interfaces at the switches to avoid any impact to its operation. Never touch HA config.
Toshi
@Toshi_Esumi Thanks for the response. Yes your right we should not touch the ha settings as much as possible and try doing other things.
We have 1100e hw fgt, using physical Mgmt port being used to access.
Under "config sys int" i saw mgmt port config except the ip address which lost, re-added but didn't work.
Hi @Zayd,
Could you share the ticket number?
Thanks.
Do you mean TAC ticket no?
R u from fortinet tac?
User | Count |
---|---|
2554 | |
1356 | |
795 | |
647 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.