Hi everyone
I have two firewalls 201G model version 7.4.6, when i configure vdom partitioning with separate two cluster root and rnd. Root is primary in cluster 1 and rnd is primary in cluster 2, but rnd didn't work. I show HA configured, which is no problem; status and role are correct. When i connect the wan port to rnd primay (cluster 2), the port status is down and pppoe is not up, but when i connect the same port on cluster 1, it's up, but pppoe status is installing. Does anybody meet that case, and how can i fix that
Thanks for your help
hi,
if im not mistaken, you would require to have both FGT connected identically to downstream ( to provide redundacy in case of failover among other ) and then you assign the interface to the VDOM/device that you want to handle the traffic.
Created on 10-27-2025 11:29 PM Edited on 10-27-2025 11:34 PM
Yes, I also follow that document when I configure, but the vdom in cluster 2 does not work, and the port status is down as I said above.
Now, I moved two VDOMs to make them active on the primary firewall. It's working normally.
i would suggest not connecting any device directly in a FGT, especially when you have a cluster.
instead try connecting those devices in a L2 device (preferably) each in it's own VLAN and then connect the FGTs to the same L2/switch.
Thanks for your suggestion, but I wonder why I follow the guide and the status shows correctly. Where was I wrong in this case? And what do I need to check, because the solution " I moved two VDOMs to make them active on the primary firewall. It's working normally." is temporary. Can you give me more suggestion?
try assigning the port that you are connecting on FGT B which is the PRI vcluster for rnd and SEC for root, to rnd VDOM and see if it works.
I also tried yesterday. When I connect with the solution you said above, the port status is up, but pppoe status is "installing" forever. However, if I assign a static IP via an internet leased line, it works well. Do you think the cause is fortigate firmware?
have a read at this article as per the pppoe problem, starting with the HA group id, https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-Troubleshooting-PPPoE-connection-fai...
Created on 10-28-2025 02:18 AM Edited on 10-28-2025 02:20 AM
Thanks, I use group ID 100 for HA. When I tested yesterday, I didn't see "PADO" response, although I connected both ports on the primary and secondary. I think it has a problem when rnd primary on pppoe process due to wrong forward pppoe packets. Instead of forward to rnd primary node it forward to rnd secondary note. it due to "installing" status. I aslo test pppoe on my laptop, it works.
| User | Count |
|---|---|
| 2702 | |
| 1415 | |
| 810 | |
| 716 | |
| 455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.