Hot!HA - Monitoring

Author
Domsi
New Member
  • Total Posts : 8
  • Scores: 0
  • Reward points: 0
  • Joined: 2018/05/11 05:42:53
  • Status: offline
2020/02/07 06:32:11 (permalink)
0

HA - Monitoring

Hi.

It is the first time I have setup a FortiGate 100F Cluster (FortiOS 6.2.3). I followed the tutorials for "HA" and selected "active-passive" for the FortiGate. I have setup the "ha1, ha2" interfaces an connected them. Then I have selected the "wan1" interface for monitoring. Basically the HA-Settings are working - I have got the master and the slave unit. If "wan1" loosing the connection (pulling cable out / or restart of master) it switches to slave which becomes new primary. But if "wan1" of old primary is restored I will get no connection from outside - only if I'm pulling out "wan1" cable of slave.
 
F1 = master -> monitoring "wan1"
F2 = slave -> monitoring "wan1"
 
F1 > wan1 is lost > F2 = primary, F1 = slave ... all connections are now running correctly over F2.
Then F1 > wan1 is restored > F1 = primary, F2 = slave ... I can only connect to F1 via MGMT (MGMT of F2 is not responding).. but I'm not able to ping the public IP of wan1, and I'm also not able to connect via SSL-VPN. I have pull out "wan1-cable" of F2 > then I'm able to connect to the F1 from public (ping on public IP, VPN)...
 
Is there something I have to consider or there are some settings missing?
#1

3 Replies Related Threads

    Toshi Esumi
    Expert Member
    • Total Posts : 1928
    • Scores: 168
    • Reward points: 0
    • Joined: 2014/11/06 09:56:42
    • Status: offline
    Re: HA - Monitoring 2020/02/07 06:46:52 (permalink)
    0
    If you want the previous master to take the master roll over when its wan1 recovered, you need to set priority on that unit higher to override. 
    https://help.fortinet.com/fos60hlp/60/Content/FortiOS/fortigate-high-availability/HA_FGCP_override.htm?Highlight=ha%20override
     
    #2
    Domsi
    New Member
    • Total Posts : 8
    • Scores: 0
    • Reward points: 0
    • Joined: 2018/05/11 05:42:53
    • Status: offline
    Re: HA - Monitoring 2020/02/08 01:08:00 (permalink)
    0
    F1 => Priority = 250
    F2 => Priority = 200
    (Screenshot attached) --> edge-primary = master = higher serial number
     
    The F1 becomes, after restored "wan1", correctly the master. I can only connect to F1 via MGMT (F2 MGMT not respondig), the ha status (GUI and CLI) shows F1 as master. But I can't reach the FortiGate from public (no ping on public IP, no VPN connection possible). I have to pull out "wan1 cable" of F2 => now I can access the F1 from public.

    It looks like that F1 = primary but F2 is still active > because if I'm connected to an internal port of the F2 the traffic still goes over this F2 => Ping to internal LAN port is possible, traffic to the inernet is still possible.

    The same happens If I reboot the F1. It comes up again, becomes the master and I can never connect from public. I have to pull out "wan1 cable" of F2 => then I can connect again.... they are in an external datacenter, so I have to drive there every time...
    post edited by Domsi - 2020/02/08 01:09:47

    Attached Image(s)

    #3
    Toshi Esumi
    Expert Member
    • Total Posts : 1928
    • Scores: 168
    • Reward points: 0
    • Joined: 2014/11/06 09:56:42
    • Status: offline
    Re: HA - Monitoring 2020/02/11 00:12:56 (permalink)
    0
    After setting priorities then enabling override, what's in under "config sys ha" now?
    You can see what's going on on either side with "diag sys ha history read" with timestamps. They can probably tell why they don't fail back.
    #4
    Jump to:
    © 2020 APG vNext Commercial Version 5.5