HA configuration
High Availability
end
3. From either FIM interface module, enter the following command to confirm that the FortiGate-7000 is in HA
mode:
diagnose sys ha status
The
password
and
group-id
are unique for each HA cluster and must be the same on all FIM modules.
If a cluster does not form, one of the first things to check are
groupd-id
and re-enter the password on both
FIM interface modules.
Configure HA on the FIM interface modules in the second FortiGate-7000 (chassis 2)
1. Repeat the same HA configuration settings on the FIM interfaces modules in the second chassis except set the
chassis ID to 2.
config system ha
set mode a-p
set password <password>
set group-id <id>
set chassis-id 2
set hbdev M1/M2
end
2. From any FIM interface module, enter the following command to confirm that the cluster has formed and all of the
FIM modules have been added to it:
diagnose sys ha status
The cluster has now formed and you can add the configuration and connect network equipment and start
operating the cluster. You can also modify the HA configuration depending on your requirements.
Verifying that the cluster is operating correctly
Enter the following CLI command to view the status of the cluster. You can enter this command from any
module's CLI. The HA members can be in a different order depending on the module CLI from which you enter
the command.
If the cluster is operating properly the following command output should indicate the primary and backup (master
and slave) chassis as well as primary and backup (master and slave) modules. For each module, the
state
portion of the output shows all the parameters used to select the primary FIM module. These parameters include
the number FPM modules that the FIM module is connecting to that have failed, the status of any link
aggregation group (LAG) interfaces in the configuration, the state of the interfaces in the FIM module, the traffic
bandwidth score for the FIM module (the higher the traffic bandwidth score the more interfaces are connected to
networks, and the status of the management links.
diagnose
sys
ha
status
==========================================================================
Current slot: 1
Module SN: FIM04E3E16000085
Chassis HA mode: a-p
Chassis HA information:
[Debug_Zone HA information]
HA group member information: is_manage_master=1.
FG74E83E16000015:
Slave, serialno_prio=1, usr_priority=128, hostname=CH15
FG74E83E16000016: Master, serialno_prio=0, usr_priority=127, hostname=CH16
HA member information:
CH16(FIM04E3E16000085), Master(priority=0), uptime=78379.78, slot=1, chassis=2(2)
61
FortiGate-7000
Fortinet Technologies Inc.