A real-life situation
FGT1 is now the gateway, VPN hub and security inspection point for the whole company. If its power supply fails, everything stops. A second, identical FortiGate in an HA cluster removes that single point of failure, and firmware upgrades no longer need a full outage.
- 1. Normally: FGT1-A is primary and owns the virtual MACs; all traffic passes through it.
- 2. After a failure: FGT1-B takes over the same addresses and virtual MACs and sends gratuitous ARPs, so switches update quickly.
Configure the cluster
config system ha
set group-name "FGT1-HA"
set mode a-p
set password <ha-password>
set hbdev "port7" 50 "port8" 50
set session-pickup enable
set override disable
set priority 200
set monitor "port1" "port2"
endConfigure the same on FGT1-B with priority 100. Group name, mode and password must match. Two heartbeat links (port7, port8) avoid a split brain if one cable fails. Once the units see each other, the secondary receives the primary's configuration automatically.
Who becomes primary?
What survives a failover
- Configuration: always synchronised.
- IP and MAC addresses: interfaces use virtual MACs, so neighbours keep their ARP entries; the new primary sends gratuitous ARPs.
- Sessions: only with
session-pickup enable. Without it, existing connections drop and users reconnect. Sessions handled by proxy-based inspection generally aren't picked up. - IPsec tunnels: SAs are synchronised, so tunnels normally stay up.
Check the cluster
FGT1 # get system ha status HA Health Status: OK Model: FortiGate-VM64 Mode: HA A-P Group Name: FGT1-HA ... Primary selected using: <2026/10/11 09:12:44> vcluster-1: FGVM0000000A is selected as the primary because it has the largest value of uptime. ... Configuration Status: FGVM0000000A(updated 2 seconds ago): in-sync FGVM0000000B(updated 3 seconds ago): in-sync ... Primary : FGT1-A , FGVM0000000A, HA cluster index = 0 Secondary : FGT1-B , FGVM0000000B, HA cluster index = 1
diagnose sys ha checksum cluster compares the checksums on each unit.Why it works this way
A firewall holds state: sessions, NAT mappings and VPN keys. Simply swapping in a spare box would drop all of it. Synchronising configuration, sessions and SAs over heartbeat links, and sharing virtual MAC addresses, lets the standby continue almost exactly where the primary stopped.
Common mistakes
- A single heartbeat link: if it fails, both units think they are alone and both become primary (split brain).
- Forgetting session pickup and being surprised that every connection drops on failover.
- Enabling override without understanding it, causing a second failover when the preferred unit returns.
- Different firmware or licences on the two units.
Key takeaways
- FGCP clusters identical units with heartbeats, configuration sync and virtual MACs.
- Active-passive is the common mode; active-active shares inspection work.
- Election (override off): monitored interfaces, uptime, priority, serial number.
- Session pickup keeps connections alive; get system ha status shows health and sync.
Check yourself
Override is disabled. FGT1-A (priority 200) reboots and returns; FGT1-B (priority 100) has been primary meanwhile. Who is primary afterwards?
The primary's port2 (monitored) cable is unplugged. What happens?
After a failover, every user has to reconnect their sessions. Which setting was missing?