A-P FGCP cluster
FortiGates work in a cluster setup in an active-passive (A-P) manner. There is one primary unit in the cluster that is responsible for traffic forwarding. You can have one or more standby units, which have the exact same configuration as the primary. The intention is to reduce the impact of device or corresponding connectivity failure to mission-critical traffic. Failover conditions are L2 connectivity failure, L3 connectivity failure, or power failure on the primary unit. As soon as the conditions are met, traffic starts to flow from the standby device. For IPS inspection, if you enable session synchronization, the existing sessions continue flow from the secondary device.
SSL deep inspection sessions do not continue after failover as the cluster does not synchronize SSL deep inspection sessions.