Hello all!
I am attempting to configure an address on each of my peer members within a HA cluster that will not be a shared address (allowing out of band management). My devices are 1500D's running 5.4.3 build1111. I have tried to configure the following:
config system interface
edit "mgmt1"
set ip X.X.X.X 255.255.255.0
set allowaccess ping https ssh http fgfm
end
config system ha
set group-name alpha
set mode a-p
set ha-mgmt-status enable
set ha-mgmt-interface "mgmt1"
set ha-mgmt-interface-gateway X.X.X.X
end
I have made sure the gateway is on the same subnet as the address of the interface, but for whatever reason its like the interface doesn't take the gateway as I can't ping the address. If I configure a static route (without the above, as it won't let you have a static route to an assigned mgmt HA interface), then it works just fine. Is there something I'm missing? I've searched around (which is how I got the above commands, I have all of a few hours of training on fortigates....), but so far no luck =(. Thanks for any help anyone can offer!
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Think I found my issue.... For some reason if I assign the address to the interface BEFORE I set the mgmt. interface gateway, I have to reboot for it to take effect. If I assign the gateway before I set the ip on the interface, then it seems to work right away. Just posting this in case anyone else has the same issue.
I have a 1500D on 5.4.3 and its configured the same exact way and it works (although we are running VDOMs). Are you sure its not something on the network? Can you plug a laptop directly into the mgmt1 port on same subnet and ping it?
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1662 | |
1077 | |
752 | |
443 | |
220 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.