Hello,
The problem concerns the vpn.certificate.local object on devices in the HA A-P cluster based on FortiOS 7.2.10. The object is not synchronized in the cluster, which causes out of sync.
What was done?
1. Manual recalculation and re-execution of synchronization on both devices does not bring results.
2. Restarting the devices on both sides does not bring results.
3. Disconnecting the cluster, hard resetting the secondary device, editing the configuration downloaded from the primary device and uploading the configuration to the secondary device so that the configurations are identical 1:1 and reconnecting the cluster, also does not bring results
4. Using the technical tip from the link below was done and also does not bring results:
All of the above methods help only for 3 minutes, then the same object stops being synchronized again, updating to FortiOS 7.4.5 gives the same effect, i.e. the problem returns.
Any logical explanation for this?
Best regards,
Adrian
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
on step 3 did you follow as below:-
factory reset the secondary box
download the config file of primary box
change the HA parameters only and hostname
restore the primary config post ha parameters changes on the sec box
connect the HA
did it made the device come to sync ?
Hi sjoshi,
I did exactly as you described above and the cluster resynchronized without any problems, but after a few minutes the vpn certificate.local object got out of sync again similarly to the previous methods I described
Best regards,
Adrian
can you share below output:-
show full | grep private
Is there any custom cert install on the FGT
show full | grep private on both devices is disabled.
Yes, there are some non-standard certificates like ACME or DigiCert, but on both devices before and after recalculation/sync the same checksums are present without any changes. There is command to check before and after operation:
diagnose sys ha checksum show root vpn.certificate.local
The symptom is that the sync lasts for a few minutes and then the object is desynchronized and then it resynchronizes and then desynchronizes again after a few minutes
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1710 | |
1093 | |
752 | |
446 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.