Re: Choice between active/active and active/passive mode FORTIGATE 50E
2021/01/16 03:18:53
(permalink)
Cluster not synchronizing has nothing to do with the HA mode.
For debugging use the CLI and these instructions from the kb.fortinet.com:
"Technical Note: Troubleshooting a checksum mismatch in a FortiGate HA cluster"
- in newer versions of FortiOS, the command is "diag sys ha check clu [|global|root]"
Comparing the list of CRCs of each config category will show you where the difference in config is. Compare the config files from master and slave for this section and correct it.
"diag sys ha checksum recalc" will sometimes help as well.
For the HA mode, my feeling is that 90% of all clusters run in a-p mode because the benefits of a-a are not crucial or needed then. Less resources, less HA traffic, not so much less throughput (which would be the strongest argument pro a-a mode).
Ede
" Kernel panic: Aiee, killing interrupt handler!"