Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
redhat9
New Contributor

Choice between active/active and active/passive mode FORTIGATE 50E

Hi, i have setup active active cluster fortigate 50E but ha is out of sync.

 

i found a littleexplanatin to setup this cluster in coobook but it's not a complete tutorial and it's my first time with cluster fortinet.

 

can you explain me in details how to setup active/active cluster and i want to know if it's respond to my need in fact or perhaps active/passive is more adapt to my needs.

 

Regards

6 REPLIES 6
ede_pfau
Esteemed Contributor III

Cluster not synchronizing has nothing to do with the HA mode.

For debugging use the CLI and these instructions from the kb.fortinet.com:

"Technical Note: Troubleshooting a checksum mismatch in a FortiGate HA cluster"

 - in newer versions of FortiOS, the command is "diag sys ha check clu [|global|root]"

 

Comparing the list of CRCs of each config category will show you where the difference in config is. Compare the config files from master and slave for this section and correct it.

 

"diag sys ha checksum recalc" will sometimes help as well.

 

For the HA mode, my feeling is that 90% of all clusters run in a-p mode because the benefits of a-a are not crucial or needed then. Less resources, less HA traffic, not so much less throughput (which would be the strongest argument pro a-a mode).


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
redhat9

Hello. Thanks a lot for your reply. I talk with my collegue and we need just ha activé passive. I have to go to datacenter to setup. Regards.
ede_pfau
Esteemed Contributor III

you'll see it's not a big deal to change the mode. Would you please report if it caused a reboot? Not sure about it.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Yurisk
Valued Contributor

If you are not sure then you do NOT need Active/passive mode. Switch to A-P and everything will just work. 

Yuri https://yurisk.info/  blog: All things Fortinet, no ads.
Yuri https://yurisk.info/ blog: All things Fortinet, no ads.
ede_pfau
Esteemed Contributor III

@Yurisk: ??

I was not sure if changing the setting will cause a reboot. Just curious.


Ede

"Kernel panic: Aiee, killing interrupt handler!"
Ede"Kernel panic: Aiee, killing interrupt handler!"
Yurisk
Valued Contributor

@ede_pfau - no idea either, never had to change mode to A/A on working gear, actually - never had to use Active-Active in Fortigates in production, I strive to solve/prevent problems, not to create them, who wants load balancing - have load balancers for that :)  

Yuri https://yurisk.info/  blog: All things Fortinet, no ads.
Yuri https://yurisk.info/ blog: All things Fortinet, no ads.
Labels
Top Kudoed Authors