Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
suthomas1
New Contributor

session enable with ha pair

Hello All, We have a pair of fortigate 800 which is not having its sessions in sync with each other. How do we make this work so secondary has the session details if failover happens & will the process of doing this cause any issues? This is running in production now. Thank you in advance.
Suthomas
Suthomas
7 REPLIES 7
rwpatterson
Valued Contributor III

Things to check:
  • Make sure both units are the same revision
  • Make sure both units are running the same version of code
  • Make sure both units have the same HA settings
  • Make sure both units are using the same port Check these and get back to us, please. Include firmware level if possible.
  • Bob - self proclaimed posting junkie!
    See my Fortigate related scripts at: http://fortigate.camerabob.com

    Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
    suthomas1
    New Contributor

    Thank you for the response. Yes , all of you the stated things are correct & is in the existing pair. Running code is 4.0 something, i can' t exactly recall though. Please advise on how to enable the sync & if there will be any impact for that.
    Suthomas
    Suthomas
    SgtMalicious

    Check the documentation, there are several ways to setup session syncs. Basic configuration is this:
     config system ha
       set session-pickup enable
     
    ede_pfau
    SuperUser
    SuperUser

    Session sync does have severe implications - the load on the FGT CPUs is higher, and so is the traffic across the HA link. Your decision if that is worth the session failover (which should occur only rarely).

    Ede

    "Kernel panic: Aiee, killing interrupt handler!"
    Ede"Kernel panic: Aiee, killing interrupt handler!"
    suthomas1
    New Contributor

    Thank you for the replies. If we enable this, will it cause any impact to live traffic when we add this feature? Our firewall pair is passing live traffic and complete shutdown is not possible, so we are looking at the best way to incorporate this feature in , without causing any problems for live traffic.
    Suthomas
    Suthomas
    ede_pfau
    SuperUser
    SuperUser

    I' ve never (consciously) changed the session pickup mode on a production FGT cluster. So there may be a short interruption of traffic but I doubt it - only the secondary unit should be affected. The docs do not clearly state what happens when activating this. Nonetheless, please read up on the session failover (session pick-up) feature in the FortiOS Handbook. There is quite a lot of traffic which is not covered by session pickup, like UDP, AV scanned, or SSL VPN.

    Ede

    "Kernel panic: Aiee, killing interrupt handler!"
    Ede"Kernel panic: Aiee, killing interrupt handler!"
    suthomas1
    New Contributor

    Thank you for the reply. handbook doesn' t give too much details on how this will impact. I am trying to see out of the active/passive device, which one should this be first put on. (typically it should be on the active device) , Will it cause interruption to normal data flow?
    Suthomas
    Suthomas
    Labels
    Top Kudoed Authors