
90
Fortinet Inc.
Managing the HA cluster
High availability
Use the following procedure to make configuration changes to the primary FortiGate
unit and then synchronize the configuration of the subordinate units.
1
Connect to the cluster and log into the web-based manager or CLI.
2
Make configuration changes as required.
3
Connect to the CLI of each of the subordinate units in the cluster.
To connect to subordinate units, see
“Managing individual cluster units” on page 89
.
4
Use the
execute ha synchronize
command to synchronize the configuration of
the subordinate unit.
5
Repeat steps
3
and
4
for all of the subordinate units in the HA cluster.
Returning to standalone configuration
Repeat this procedure for each FortiGate unit in the HA cluster. To return to
standalone configuration:
1
Connect to the web-based manager.
2
Go to
System > Config > HA
.
3
Select Standalone Mode and select Apply.
The FortiGate unit exits from HA mode and returns to standalone mode.
Replacing a FortiGate unit after fail-over
A failover can occur due to a hardware or software problem. When a failover occurs,
you can attempt to restart the failed FortiGate unit by cycling its power. If the FortiGate
unit starts up correctly, it rejoins the HA cluster, which then continues to function
normally. If the FortiGate unit does not restart normally or does not rejoin the HA
cluster, you must take it out of the network and either reconfigure or replace it.
Once the FortiGate unit is reconfigured or replaced, change its HA configuration to
match that of the FortiGate unit that failed and connect it back into the network. The
reconnected FortiGate unit then automatically joins the HA cluster.
Table 16:
execute ha synchronize
keywords
Keyword
Description
config
Synchronize the FortiGate configuration. This includes normal system
configuration, firewall configuration, VPN configuration and so on stored in the
FortiGate configuration file.
avupd
Synchronize the antivirus engine and antivirus definitions received by the
primary unit from the FortiResponse Distribution Network (FDN).
attackdef
Synchronize NIDS attack definition updates received by the primary unit from
the FDN.
weblists
Synchronize web filter lists added to or changed on the primary unit.
emaillists
Synchronize email filter lists added to or changed on the primary unit.
resmsg
Synchronize replacement messages changed on the primary unit.
ca
Synchronize CA certificates added to the primary unit.
localcert
Synchronize local certificates added to the primary unit.
all
Synchronize all of the above.
Summary of Contents for FortiGate 400
Page 13: ...Contents FortiGate 400 Installation and Configuration Guide 13 Glossary 295 Index 299 ...
Page 14: ...Contents 14 Fortinet Inc ...
Page 44: ...44 Fortinet Inc Next steps Getting started ...
Page 74: ...74 Fortinet Inc Transparent mode configuration examples Transparent mode installation ...
Page 148: ...148 Fortinet Inc Providing DHCP services to your internal network Network configuration ...
Page 168: ...168 Fortinet Inc Customizing replacement messages System configuration ...
Page 200: ...200 Fortinet Inc Content profiles Firewall configuration ...
Page 258: ...258 Fortinet Inc Logging attacks Network Intrusion Detection System NIDS ...
Page 294: ...294 Fortinet Inc Configuring alert email Logging and reporting ...
Page 298: ...298 Fortinet Inc Glossary ...
Page 308: ...308 Fortinet Inc Index ...