- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
secondary forti in HA active active is not accessible when I disconnect the primary
Community,
I have the below:
2 fortigate 200F ( HA cluster active active 1st is primary and 2nd is secondary) connected to a core switch with 2 connection each firewall ( 4 connection in total).
the issue is when i try to test the HA active active and I remove the forti primary connection with the core switch, I have no access to the secondary forti ( cannot ping over the ip address that I gave for the both 200F).
The configuration in the core switch is with port channel (channel group) mode active and in the forti is 802.3ad aggregate.
Please Help.
Kind regards
Solved! Go to Solution.
- Labels:
-
FortiGate
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @firas ,
Any HA deployment highly depend on the network design. Based on behavior, looks like your network only works on the primary unit. When primary down, the network itself did not failover to the secondary unit.
And you did mentioned about 2 ports suspended in ethernet channel. I believe it suspended on the switch level to prevent looping. Which may triggered by Spanning Tree Protocol.
This link may be helpful to help you troubleshoot on the issue:
https://kb.fortinet.com/kb/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=FD50620
https://kb.fortinet.com/kb/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=FD47572
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
To add to this, I found that I have 2 ports suspended in the ethernet channel for the secondary forti.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @firas ,
Any HA deployment highly depend on the network design. Based on behavior, looks like your network only works on the primary unit. When primary down, the network itself did not failover to the secondary unit.
And you did mentioned about 2 ports suspended in ethernet channel. I believe it suspended on the switch level to prevent looping. Which may triggered by Spanning Tree Protocol.
This link may be helpful to help you troubleshoot on the issue:
https://kb.fortinet.com/kb/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=FD50620
https://kb.fortinet.com/kb/microsites/microsite.do?cmd=displayKC&docType=kc&externalId=FD47572
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you for your reply. I followed the below link and it solved my problem.
Technical Tip: Aggregate link configuration topolo... - Fortinet Community
