Monitoring cluster units for failover

Fields                      Description

The HA state (hello, work, or standby) and HA heartbeat IP address of the cluster unit that you have logged into in virtual cluster 1. If virtual domains are not enabled, vcluster 1 displays information for the cluster. If virtual domains are enabled, vcluster 1 displays information for virtual cluster 1.

The HA heartbeat IP address is 169.254.0.2 if you are logged into the primary unit of virtual cluster 1 and 169.254.0.1 if you are logged into a subordinate unit of virtual cluster 1.

vcluster 1 also lists the primary unit (master) and subordinate units (slave) in vir- tual cluster 1. The list includes the cluster index and serial number of each cluster unit in virtual cluster 1. The cluster unit that you have logged into is at the top of the list.

vcluster 1

Master Slave

If virtual domains are not enabled and you connect to the primary unit CLI, the HA state of the cluster unit in virtual cluster 1 is work. The display lists the cluster units starting with the primary unit.

If virtual domains are not enabled and you connect to a subordinate unit CLI, the HA state of the cluster unit in virtual cluster 1 is standby. The display lists the cluster units starting with the subordinate unit that you have logged into.

If virtual domains are enabled and you connect to the virtual cluster 1 primary unit CLI, the HA state of the cluster unit in virtual cluster 1 is work. The display lists the cluster units starting with the virtual cluster 1 primary unit.

If virtual domains are enabled and you connect to the virtual cluster 1 subordinate unit CLI, the HA state of the cluster unit in virtual cluster 1 is standby. The display lists the cluster units starting with the subordinate unit that you are logged into.

vcluster 2

Master Slave

vcluster 2 only appears if virtual domains are enabled. vcluster 2 displays the HA state (hello, work, or standby) and HA heartbeat IP address of the cluster unit that you have logged into in virtual cluster 2. The HA heartbeat IP address is 169.254.0.2 if you are logged into the primary unit of virtual cluster 2 and 169.254.0.1 if you are logged into a subordinate unit of virtual cluster 2.

vcluster 2 also lists the primary unit (master) and subordinate units (slave) in vir- tual cluster 2. The list includes the cluster index and serial number of each cluster unit in virtual cluster 2. The cluster unit that you have logged into is at the top of the list.

If you connect to the virtual cluster 2 primary unit CLI, the HA state of the cluster unit in virtual cluster 2 is work. The display lists the cluster units starting with the virtual cluster 2 primary unit.

If you connect to the virtual cluster 2 subordinate unit CLI, the HA state of the cluster unit in virtual cluster 2 is standby. The display lists the cluster units starting with the subordinate unit that you are logged into.

 

Examples

The following example shows get system ha status output for a cluster of two FortiGate-5001SX units operating in active-active mode. The cluster group ID, session pickup, load balance all, and the load balancing schedule are all set to the default values. The device priority of the primary unit is also set to the default value. The device priority of the subordinate unit has been reduced to 100. The host name of the primary unit is 5001_ Slot_4. The host name of the subordinate unit in is 5001_Slot_3.

The command output was produced by connecting to the primary unit CLI (host name 5001_Slot_4).

Model: 5000

Mode: a-a

Group: 0

Debug: 0

ses_pickup: disable load_balance: disable schedule: round robin

Master:128 5001_Slot_4 FG50012204400045 1

Slave :100 5001_Slot_3 FG50012205400050 0 number of vcluster: 1

vcluster 1: work 169.254.0.2

Master:0 FG50012204400045

Slave :1 FG50012205400050

The following command output was produced by using execute HA manage 0 to log into the subordinate unit CLI of the cluster shown in the previous example. The host name of the subordinate unit is 5001_Slot_3.

Model: 5000

Mode: a-a

Group: 0

Debug: 0

ses_pickup: disable load_balance: disable schedule: round robin

Slave :100 5001_Slot_3 FG50012205400050 0

Master:128 5001_Slot_4 FG50012204400045 1 number of vcluster: 1

vcluster 1: work 169.254.0.2

Slave :1 FG50012205400050

Master:0 FG50012204400045

The following example shows get system ha status output for a cluster of three FortiGate-5001 units operating in active-passive mode. The cluster group ID is set to 20 and session pickup is enabled. Load balance all and the load balancing schedule are set to the default value. The device priority of the primary unit is set to

  1. 200. The device priorities of the subordinate units are set to 128 and 100. The host name of the primary unit is

5001_Slot_5. The host names of the subordinate units are 5001_Slot_3 and 5001_Slot_4.

Model: 5000

Mode: a-p

Group: 20

Master:200 5001_Slot_5 FG50012206400112 0
Slave :100 5001_Slot_3 FG50012205400050 1
Slave :128 5001_Slot_4 FG50012204400045 2

 

Debug: 0 ses_pickup: enable load_balance: disable schedule: round robin

number of vcluster: 1 vcluster 1: work 169.254.0.1

Master:0 FG50012206400112

Slave :1 FG50012204400045

Slave :2 FG50012205400050

The following example shows get system ha status output for a cluster of two FortiGate-5001 units with virtual clustering enabled. This command output was produced by logging into the primary unit for virtual cluster 1 (hostname: 5001_Slot_4, serial number FG50012204400045).

The virtual clustering output shows that the cluster unit with host name 5001_Slot_4 and serial number FG50012204400045 is operating as the primary unit for virtual cluster 1 and the subordinate unit for virtual cluster 2.

For virtual cluster 1 the cluster unit that you have logged into is operating in the work state and the serial number of the primary unit for virtual cluster 1 is FG50012204400045. For virtual cluster 2 the cluster unit that you have logged into is operating in the standby state and the serial number of the primary unit for virtual cluster 2 is FG50012205400050.

Model: 5000

Mode: a-p

Group: 20

Debug: 0 ses_pickup: enable load_balance: disable schedule: round robin

Master:128 5001_Slot_4 FG50012204400045 1

Slave :100 5001_Slot_3 FG50012205400050 0 number of vcluster: 2

vcluster 1: work 169.254.0.2

Master:0 FG50012204400045

Slave :1 FG50012205400050 vcluster 2: standby 169.254.0.1

Slave :1 FG50012204400045

Master:0 FG50012205400050

The following example shows get system ha status output for the same cluster as shown in the previous example after using execute ha manage 0 to log into the primary unit for virtual cluster 2 (hostname: 5001_ Slot_3, serial number FG50012205400050).

Model: 5000

Mode: a-p

Group: 20

Debug: 0 ses_pickup: enable load_balance: disable schedule: round robin

Slave :100 5001_Slot_3 FG50012205400050 0

Master:128 5001_Slot_4 FG50012204400045 1 number of vcluster: 2

vcluster 1: standby 169.254.0.2

Slave :1 FG50012205400050

Master:0 FG50012204400045 vcluster 2: work 169.254.0.1

Master:0 FG50012205400050

Slave :1 FG50012204400045

The following example shows get system ha status output for a virtual cluster configuration where the cluster unit with hostname: 5001_Slot_4 and serial number FG50012204400045 is the primary unit for both virtual clusters. This command output is produced by logging into cluster unit with host name 5001_Slot_4 and serial number FG50012204400045.

Model: 5000

Mode: a-p

Group: 20

Debug: 0 ses_pickup: enable load_balance: disable schedule: round robin

Master:128 5001_Slot_4 FG50012204400045 1

Slave :100 5001_Slot_3 FG50012205400050 0 number of vcluster: 2

vcluster 1: work 169.254.0.2

Master:0 FG50012204400045

Slave :1 FG50012205400050 vcluster 2: work 169.254.0.2

Master:0 FG50012204400045

Slave :1 FG50012205400050

This entry was posted in FortiOS 5.4 Handbook and tagged , , on by .

About Mike

Michael Pruett, CISSP has a wide range of cyber-security and network engineering expertise. The plethora of vendors that resell hardware but have zero engineering knowledge resulting in the wrong hardware or configuration being deployed is a major pet peeve of Michael's. This site was started in an effort to spread information while providing the option of quality consulting services at a much lower price than Fortinet Professional Services. Owns PacketLlama.Com (Fortinet Hardware Sales) and Office Of The CISO, LLC (Cybersecurity consulting firm).

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.