Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
digvijay2050
New Contributor

Fortigate HA Issue - URGENT

Hello guys,

 

I've 2 600D firewall in HA (Active-Active) mode and we've 3 ISP. Between each ISP connection, there is a switch so that we can get two cable outputs for each firewall.

For temporary reasons, I had changed the ISP2 interface IP to all 0.0.0.0 (and also disconnected the cable) to test something else. And now, when I reassign the public IP to the same interface, it says "This IP is already in use by device 00:09:0f:09:00:15". This is Fortinet MAC address.

What am I missing here?

 

Details: HA: Active-Active

OS: 5.4.2

VDOM: Yes, 7 No's.

 

How can I fix this? Please help.

8 REPLIES 8
hklb
Contributor II

Hi,

 

The output message is on web interface or in CLI ?

 

Is your WAN interface is a VLAN?

 

Do you have the "sync-config enable" in conf sys ha?

 

is your cluster in in sync ?

 

Mac address "00:09:0f:09:00:15" is the mac address of master of slave device ?

 

 

digvijay2050

That is the output message I get on the Web Interface. On CLI it took the IP, but there was no internet connectivity.

 

No, its not a VLAN. Its an ISP Ethernet cable coming in, which then connects to an unmanaged switch and then two cables from the unmanaged switch to each firewall.

 

Yes, sync-config is enabled.

 

Upon research I found out that the MAC belongs to the ISP1 port. But I checked the config of ISP1 in both GUI and CLI and there is no trace of an IP Conflict between ISP1 and ISP2 ports.

barryh
New Contributor

I am not a expert, but maybe the relation between MAC and IP is still in a table, Arp Tabel, NAT table

digvijay2050

I rebooted the HA cluster. Shouldn't that clear the NAT/ARP table? Correct me if I'm wrong.

rwpatterson
Valued Contributor III

Try rebooting the switch for the IPS's links.

Bob - self proclaimed posting junkie!
See my Fortigate related scripts at: http://fortigate.camerabob.com

Bob - self proclaimed posting junkie!See my Fortigate related scripts at: http://fortigate.camerabob.com
digvijay2050

Yes, done that too.

hklb

Have you already check if the IP is set in anywhere in your configuration file ?

 

config vdom

edit <yourVDOM>

show full | grep <IpYoutryToSet>

 

 

When you try to configure in CLI, is your configuration is accepted ? Are you able to do ping?

 

Do you have more than one IP on your public IP ? if yes, try to configure an unused IP address and :

- exec ping <PublicIpAddressYouTryToConfigure>

- diagnose ip arp list | grep <PublicIpAddressYouTryToConfigure>

-> what is the state of this arp entry?

 

Maybe you can try to upgrade to 5.4.4.. 5.4.4 has a lot of bug, so I think the 5.4.2 is worst... 

 

 

barryh

Did you verify it? get system arp diagnose sys session list above command can be used with a filter

diagnose sys session filter ?

Labels
Top Kudoed Authors