Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Sassoli
New Contributor

Troubleshooting cluster members individual connectivity

Good morning everyone,

We have a Fortigate cluster, members model 200F.

Recently, we had to move one of the two members to a secondary data center.

We then performed a failover test, and everything worked correctly except for one interface; we can no longer reach any hosts connected to this interface from the recently moved member.

The problematic interface is a LAG (Link Aggregation Group) of two ports, connected to a core switch.

This interface serves a dmz network.

 

It's an active-passive cluster, and I don't have much availability for maintenance windows due to having users in different time zones. Therefore, I am struggling to troubleshoot the currently passive member.

If I try to run a traceroute without options on a host in the DMZ network, I get a response, but with three hops, the second hop, I suspect, is the active member.

If I set "execute traceroute-options device dmz" and try to run "execute traceroute 10.0.0.10," I get "1 traceroute: sendto: Network is unreachable

It even fails if i run "execute traceroute 10.0.0.1" which is the dmz gateway.

 

I tried then to traceroute from a known working network, same traceroute steps, from the passive member, they fail the same exact way, i am completely lost on how i should troubleshoot this type of problem.

 

Can somebody point me in the right direction?

 

1 REPLY 1
Atul_S
Staff & Editor
Staff & Editor

Hi Sassoli, given that the devices are in DC, they are strategically important devices. It's best to create a TAC case. 

 

Thanks,

Atul Srivastava
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors