Hot!FortiGate HA override problems

Author
unai.satec
New Member
  • Total Posts : 6
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/08/08 05:35:26
  • Status: offline
2018/08/08 05:50:51 (permalink)
0

FortiGate HA override problems

Hi!
We have two FortiGates 201E, and we have configured a cluster to get high availability, all the interfaces which are giving services are por monitoring interfaces, so if any of them break down, the master of the cluster change. the anomaly begin when you try to come up the interface of the device which has more priority than the other one, and the device that has more priority becomes the master of the cluster and as I´ve read the secondary firewall should mantain its condition as master.
Other times when we follow the same proccess, the secondary continue being the master, but that occurs in few situations. Any idea of that?
override is disabled if you think that the problem is in this fact.
#1

6 Replies Related Threads

    Toshi Esumi
    Expert Member
    • Total Posts : 1050
    • Scores: 66
    • Reward points: 0
    • Joined: 2014/11/06 09:56:42
    • Status: offline
    Re: FortiGate HA override problems 2018/08/08 09:30:30 (permalink)
    0
    Where did you read that? At least below HA handbook:
    https://docs.fortinet.com/uploaded/files/3997/fortigate-ha-56.pdf
    says below in pp.46:
    "With override enabled, the primary unit with the highest device priority will always
    become the primary unit. Whenever an event occurs that may affect primary unit selection,
    the cluster negotiates."
    It also says below in the previous page in this HA override section:
    "In most cases you should keep override disabled to reduce how often the cluster negotiates.
    Frequent negotiations may cause frequent traffic interruptions."
    For this reason we don't use HA override.
     
    Toshi
    #2
    unai.satec
    New Member
    • Total Posts : 6
    • Scores: 0
    • Reward points: 0
    • Joined: 2018/08/08 05:35:26
    • Status: offline
    Re: FortiGate HA override problems 2018/08/08 23:45:45 (permalink)
    0
    Thanks Toshi,
    So it´s impossible to mantain the master until a manual action, although the comeup of the device with more priority?
    My question was because i´ve read that if you have override disabled, the comeup of a device doesnt affect the cluster hierarchy. I think that is better to mantain the master in this situation in order to not stop the services which are being supported by the firewall.
    #3
    Toshi Esumi
    Expert Member
    • Total Posts : 1050
    • Scores: 66
    • Reward points: 0
    • Joined: 2014/11/06 09:56:42
    • Status: offline
    Re: FortiGate HA override problems 2018/08/09 09:09:19 (permalink)
    0
    The main issue is when you restores the monitored interface on the primary unit, it triggers a master election. It's not statefull and just decide based on the current conditions. Then obviously the unit that has the highest priority would be elected if override is enabled. 
    #4
    unai.satec
    New Member
    • Total Posts : 6
    • Scores: 0
    • Reward points: 0
    • Joined: 2018/08/08 05:35:26
    • Status: offline
    Re: FortiGate HA override problems 2018/08/10 02:29:31 (permalink)
    0
    I have found out that the fact is the ha-uptime-margin so if you have override disabled, what is recommended by forti, the devices will compare the time they have been in the cluster unit, there are a few situations in which this time is set to 0 and starts again. So I minimize the margin time and now the device with more priority dont interfere in the services until a manual intervention. 
    If that helped the people of the forum would be fantastic
    #5
    unai.satec
    New Member
    • Total Posts : 6
    • Scores: 0
    • Reward points: 0
    • Joined: 2018/08/08 05:35:26
    • Status: offline
    Re: FortiGate HA override problems 2018/08/10 03:38:34 (permalink)
    0
    I have found out that the fact is the ha-uptime-margin so if you have override disabled, what is recommended by forti, the devices will compare the time they have been in the cluster unit, there are a few situations in which this time is set to 0 and starts again. So I minimize the margin time and now the device with more priority dont interfere in the services until a manual intervention. 
    If that helped the people of the forum would be fantastic
     
    #6
    Toshi Esumi
    Expert Member
    • Total Posts : 1050
    • Scores: 66
    • Reward points: 0
    • Joined: 2014/11/06 09:56:42
    • Status: offline
    Re: FortiGate HA override problems 2018/08/10 08:35:33 (permalink)
    0
    If uptime difference is within the margin (ha-uptime-diff-margin), the last factor for the master election is serial numbers. It wouldn't reduce the chances for the election for random situations. The most important thing is when you intervene or manually change one of the conditions, like trying to restore the down interface, you need to understand exactly how HA would react as the result and pre-set the conditions to keep a desirable operation.
    We often (than we want to) need to break HA when troubleshooting on a slave unit at the moment.
    #7
    Jump to:
    © 2018 APG vNext Commercial Version 5.5