Fortinet black logo

Administration Guide

FortiManager high availability (HA)

FortiManager high availability (HA)

A FortiManager HA cluster consists of an active primary unit, and up to four standby secondary units. If the primary unit becomes unavailable, one of the standby secondaries will become the new primary.

In most situations, the FortiPortal provides access to the primary FortiManager in the HA cluster. Configuration changes in the primary will be synchronized to the secondary units. If no primary exists, the FortiPortal provides read-only access to the secondary units.

When a FortiManager unit with an HA configuration is added to FortiPortal, FortiPortal must be able to reach all the IP addresses that are part of the FortiManager HA cluster (including the secondary). If FortiPortal cannot reach the secondary IP address, FortiPortal cannot detect the HA switchover.

In the FortiManager table, the Mode includes the following values:

  • Standalone—the FortiManager is independent of a high-availability cluster
  • Primary—the FortiManager is the primary in a high-availability cluster
  • Secondary—the FortiManager is a secondary in a high-availability cluster

Select the HA icon to display information about the FortiManagers in this HA cluster:

The Cluster Information window provides the following information for each FortiManager in the cluster:

Field

Description

FortiManager SN

Serial number of the FortiManager

Active

Displays green arrow for an active FortiManager or a red x for an inactive FortiManager

IP Address

IP address of the FortiManager

Role

The role is Primary or Secondary.

Status

Indicates whether the FortiManager is operational

FortiManager high availability (HA)

A FortiManager HA cluster consists of an active primary unit, and up to four standby secondary units. If the primary unit becomes unavailable, one of the standby secondaries will become the new primary.

In most situations, the FortiPortal provides access to the primary FortiManager in the HA cluster. Configuration changes in the primary will be synchronized to the secondary units. If no primary exists, the FortiPortal provides read-only access to the secondary units.

When a FortiManager unit with an HA configuration is added to FortiPortal, FortiPortal must be able to reach all the IP addresses that are part of the FortiManager HA cluster (including the secondary). If FortiPortal cannot reach the secondary IP address, FortiPortal cannot detect the HA switchover.

In the FortiManager table, the Mode includes the following values:

  • Standalone—the FortiManager is independent of a high-availability cluster
  • Primary—the FortiManager is the primary in a high-availability cluster
  • Secondary—the FortiManager is a secondary in a high-availability cluster

Select the HA icon to display information about the FortiManagers in this HA cluster:

The Cluster Information window provides the following information for each FortiManager in the cluster:

Field

Description

FortiManager SN

Serial number of the FortiManager

Active

Displays green arrow for an active FortiManager or a red x for an inactive FortiManager

IP Address

IP address of the FortiManager

Role

The role is Primary or Secondary.

Status

Indicates whether the FortiManager is operational