04-04-2025 03:44 AM
Hi guys,
Need some help now. We have one fortigate HA clutser connected with two Nexus 9504 (Topology in attachment), Each fortigate has two Agg-link. We tried to test some traffics like Telnet and FTP session during Failover, the session has to be restarted (session pickup enabled on fortigate),
the test path is shown below:
remote PC>access sw>Nexus sw>router, the firewall HA cluster is passby on core Nexus sw.
After failed test, we changed the topology between Nexus and fortigate HA cluster, but still with the same result, the FTP session and telnet will disconnect during fairover. (For testing we disconnected the Agg-1 on active firewall for failover manually). The tac from fortinet said he doesn't know how the peer-link and vPort-channel will react to the MAC flap during failover. Would like to ask is there any issue with the topology design? Many thx!!!
04-04-2025 05:13 AM - edited 04-04-2025 05:13 AM
Hello @NeilL391
So bad that Fortinet support can't help you further...
Do you have 'session pickup' enable on each FortiGate HA cluster ? This feature allows the secondary unit to maintain session information, facilitating seamless failover for sessions passing through the cluster.
FGT(global)#config system ha
FGT(ha)#set session-pickup enable
04-04-2025 05:28 AM
Hi M02@rt37,
We have already enabled the session pickup on both fortigate devices, we checked all the related configurations, now we worried is about the topology issue, we don't know the traffic clearly during the failover happens.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide