Fortinet black logo

FortiGate-6000 Handbook

Configuration synchronization

Configuration synchronization

When you log into the FortiGate-6000 GUI or CLI by connecting to the IP address of the MGMT1 or MGMT2 interface, or through a console connection, you are logging into the FortiGate-6000 management board (part of the FortiGate-6000 management plane). The management board is the FortiGate-6000 config-sync master. All configuration changes must be made from the management board GUI or CLI. The management board synchronizes configuration changes to the FPCs and makes sure FPC configurations remain synchronized with the management board.

Once you have logged into the management board GUI or CLI and verified that the system is operating normally, you can view and change the configuration of your FortiGate-6000 just like any FortiGate. For example, you can configure firewall policies between any two interfaces. You can also configure aggregates of the front panel interfaces.

You can use the following command to confirm that the configurations of the management board and the FPCs are synchronized:

diagnose sys confsync showcsum

The command output contains configuration checksums for the management board and all of the FPCs. If the management board and the FPCs are synchronized, the corresponding checksums for all of the components should match.

Configuration synchronization

When you log into the FortiGate-6000 GUI or CLI by connecting to the IP address of the MGMT1 or MGMT2 interface, or through a console connection, you are logging into the FortiGate-6000 management board (part of the FortiGate-6000 management plane). The management board is the FortiGate-6000 config-sync master. All configuration changes must be made from the management board GUI or CLI. The management board synchronizes configuration changes to the FPCs and makes sure FPC configurations remain synchronized with the management board.

Once you have logged into the management board GUI or CLI and verified that the system is operating normally, you can view and change the configuration of your FortiGate-6000 just like any FortiGate. For example, you can configure firewall policies between any two interfaces. You can also configure aggregates of the front panel interfaces.

You can use the following command to confirm that the configurations of the management board and the FPCs are synchronized:

diagnose sys confsync showcsum

The command output contains configuration checksums for the management board and all of the FPCs. If the management board and the FPCs are synchronized, the corresponding checksums for all of the components should match.