Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
snobs
New Contributor II

FGSP over UDP/708 doesn´t work

Hello, I setup FGSP on 2 Fortigates. Connecting both units directly and start ethernet-based FGSP, it works. Synchronizations over UDP doesn´t work at all. Do what is missing to get UDP based FGSP working?

[ul]
  • Current state on Fortigate 1[/ul]

    port9: 10.5.22.1
    config system ha
        set hbdev "port9" 0
        set session-sync-dev "port9"
        set session-pickup enable
        set session-pickup-connectionless enable
        set session-pickup-expectation enable
        set session-pickup-nat enable
        set standalone-config-sync enable
        set override disable
        set priority 250
    end
    config system cluster-sync
        edit 1
            set peerip 10.5.21.1
            set syncvd "vdom1"
        next
    end

    diagnose sys session sync
    sync_ctx: sync_started=1, sync_tcp=1, sync_others=1,
    sync_expectation=1, sync_redir=0, sync_nat=1, stdalone_sesync=1.
    sync: create=0:0, update=0, delete=0:0, query=0
    recv: create=0:0, update=0, delete=0:0, query=0
    ses pkts: send=161176, alloc_fail=0, recv=0, recv_err=0 sz_err=0
    udp pkts: send=0, recv=0
    nCfg_sess_sync_num=5, mtu=1500
    sync_filter:
        1: vd=1, szone=0, dzone=0, saddr=0.0.0.0:0.0.0.0, daddr=0.0.0.0:0.0.0.0, sport=0-65535, dport=0:65535

    [ul]
  • Current state on Fortigate 2:[/ul]

    port9: 10.5.21.1


    config system ha
        set hbdev "port9" 0
        set session-sync-dev "port9"
        set session-pickup enable
        set session-pickup-connectionless enable
        set session-pickup-expectation enable
        set sesson-pickup-nat enable
        set standalone-config-sync enable
        set override disable
        set priority 255
    end

    config system cluster-sync
        edit 1
            set peerip 10.5.22.1
            set syncvd "vdom1"
        next
    end

    diag sys session sync
    sync_ctx: sync_started=1, sync_tcp=1, sync_others=1,
    sync_expectation=1, sync_redir=0, sync_nat=1, stdalone_sesync=1.
    sync: create=0:0, update=0, delete=0:0, query=0
    recv: create=0:0, update=0, delete=0:0, query=0
    ses pkts: send=161500, alloc_fail=0, recv=159822, recv_err=1 sz_err=0
    udp pkts: send=0, recv=0
    nCfg_sess_sync_num=5, mtu=1500
    sync_filter:

        1: vd=1, szone=0, dzone=0, saddr=0.0.0.0:0.0.0.0, daddr=0.0.0.0:0.0.0.0, sport=0-65535, dport=0:65535

     

     

    So, the Fortigate doesn´t start sending packets over UDP? What am I missing?

  • 0 REPLIES 0
    Labels
    Top Kudoed Authors