Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
AdrianPL
New Contributor

object vpn certificate local cannot synchronize

Hello,

The problem concerns the vpn.certificate.local object on devices in the HA A-P cluster based on FortiOS 7.2.10. The object is not synchronized in the cluster, which causes out of sync.

 

What was done?

 

1. Manual recalculation and re-execution of synchronization on both devices does not bring results.

 

2. Restarting the devices on both sides does not bring results.

 

3. Disconnecting the cluster, hard resetting the secondary device, editing the configuration downloaded from the primary device and uploading the configuration to the secondary device so that the configurations are identical 1:1 and reconnecting the cluster, also does not bring results

 

4. Using the technical tip from the link below was done and also does not bring results:

https://community.fortinet.com/t5/FortiGate/Troubleshooting-Tip-HA-out-of-sync-issue-due-to-vpn-cert... 

 

All of the above methods help only for 3 minutes, then the same object stops being synchronized again, updating to FortiOS 7.4.5 gives the same effect, i.e. the problem returns.

 

Any logical explanation for this?

 

Best regards,

Adrian

4 REPLIES 4
sjoshi
Staff
Staff

on step 3 did you follow as below:-

factory reset the secondary box

download the config file of primary box

change the HA parameters only and hostname

restore the primary config post ha parameters changes on the sec box

connect the HA

did it made the device come to sync ?

Let us know if this helps.
Salon Raj Joshi
AdrianPL

Hi sjoshi,

 

I did exactly as you described above and the cluster resynchronized without any problems, but after a few minutes the vpn certificate.local object got out of sync again similarly to the previous methods I described

 

 

Best regards,

Adrian

sjoshi

can you share below output:-

show full | grep private

 

Is there any custom cert install on the FGT

Let us know if this helps.
Salon Raj Joshi
AdrianPL
New Contributor

show full | grep private  on both devices is disabled.

 

Yes, there are some non-standard certificates like ACME or DigiCert, but on both devices before and after recalculation/sync the same checksums are present without any changes. There is command to check before and after operation: 

 

diagnose sys ha checksum show root vpn.certificate.local

 

The symptom is that the sync lasts for a few minutes and then the object is desynchronized and then it resynchronizes and then desynchronizes again after a few minutes

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors