Fortinet black logo

CLI Reference

config system ha

config system ha

Configure HA.

config system ha
    Description: Configure HA.
    set group-id {integer}
    set group-name {string}
    set mode [standalone|config-sync-only|...]
    set password {password}
    set key {password}
    set hbdev {user}
    set unicast-hb [enable|disable]
    set unicast-hb-peerip {ipv4-address}
    set unicast-hb-netmask {ipv4-netmask}
    set encryption [enable|disable]
    set authentication [enable|disable]
    set hb-interval {integer}
    set hb-lost-threshold {integer}
    set hello-holddown {integer}
    set gratuitous-arps [enable|disable]
    set arps {integer}
    set arps-interval {integer}
    set link-failed-signal [enable|disable]
    set uninterruptible-upgrade [enable|disable]
    set sequential-upgrade [enable|disable]
    set ha-mgmt-status [enable|disable]
    config ha-mgmt-interfaces
        Description: Reserve interfaces to manage individual cluster units.
        edit <id>
            set interface {string}
            set dst {ipv4-classnet}
            set gateway {ipv4-address}
            set gateway6 {ipv6-address}
        next
    end
    set ha-uptime-diff-margin {integer}
    set ha-direct [enable|disable]
    set vcluster-id {integer}
    set override [enable|disable]
    set priority {integer}
    set override-wait-time {integer}
    set monitor {string}
    set memory-compatible-mode [enable|disable]
end

config system ha

Parameter

Description

Type

Size

group-id

Cluster group ID . Must be the same for all members.

integer

Minimum value: 0 Maximum value: 255

group-name

Cluster group name. Must be the same for all members.

string

Maximum length: 32

mode

HA mode. Must be the same for all members. FGSP requires standalone.

option

-

Option

Description

standalone

Disable HA feature.

config-sync-only

Enable Config sync only

active-passive

Enable Active-passive mode.

password

Cluster password. Must be the same for all members.

password

Not Specified

key

key

password

Not Specified

hbdev

Heartbeat interfaces. Must be the same for all members.

user

Not Specified

unicast-hb

Enable/disable unicast heartbeat.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

unicast-hb-peerip

Unicast heartbeat peer IP.

ipv4-address

Not Specified

unicast-hb-netmask

Unicast heartbeat netmask.

ipv4-netmask

Not Specified

encryption

Enable/disable heartbeat message encryption.

option

-

Option

Description

enable

Enable heartbeat message encryption.

disable

Disable heartbeat message encryption.

authentication

Enable/disable heartbeat message authentication.

option

-

Option

Description

enable

Enable heartbeat message authentication.

disable

Disable heartbeat message authentication.

hb-interval

Time between sending heartbeat packets . Increase to reduce false positives.

integer

Minimum value: 1 Maximum value: 20

hb-lost-threshold

Number of lost heartbeats to signal a failure . Increase to reduce false positives.

integer

Minimum value: 1 Maximum value: 60

hello-holddown

Time to wait before changing from hello to work state .

integer

Minimum value: 5 Maximum value: 300

gratuitous-arps

Enable/disable gratuitous ARPs. Disable if link-failed-signal enabled.

option

-

Option

Description

enable

Enable gratuitous ARPs.

disable

Disable gratuitous ARPs.

arps

Number of gratuitous ARPs . Lower to reduce traffic. Higher to reduce failover time.

integer

Minimum value: 1 Maximum value: 60

arps-interval

Time between gratuitous ARPs . Lower to reduce failover time. Higher to reduce traffic.

integer

Minimum value: 1 Maximum value: 20

link-failed-signal

Enable to shut down all interfaces for 1 sec after a failover. Use if gratuitous ARPs do not update network.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

uninterruptible-upgrade

Enable to upgrade a cluster without blocking network traffic.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

sequential-upgrade

Enable to upgrade secondaries one by one.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

ha-mgmt-status

Enable to reserve interfaces to manage individual cluster units.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

ha-uptime-diff-margin

Normally you would only reduce this value for failover testing.

integer

Minimum value: 1 Maximum value: 65535

ha-direct

Enable/disable using ha-mgmt interface for syslog, SNMP, remote authentication (RADIUS), FortiAnalyzer, FortiManager and FortiSandbox.

option

-

Option

Description

enable

Enable using ha-mgmt interface for syslog, SNMP, remote authentication (RADIUS), FortiAnalyzer, FortiManager and FortiSandbox.

disable

Disable using ha-mgmt interface for syslog, SNMP, remote authentication (RADIUS), FortiAnalyzer, FortiManager and FortiSandbox.

vcluster-id

Cluster ID.

integer

Minimum value: 0 Maximum value: 255

override

Enable and increase the priority of the unit that should always be primary.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

priority

Increase the priority to select the primary unit .

integer

Minimum value: 0 Maximum value: 255

override-wait-time

Delay negotiating if override is enabled . Reduces how often the cluster negotiates.

integer

Minimum value: 0 Maximum value: 3600

monitor

Interfaces to check for port monitoring (or link failure).

string

Maximum length: 19

memory-compatible-mode

Enable/disable memory compatible mode.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

config ha-mgmt-interfaces

Parameter

Description

Type

Size

interface

Interface to reserve for HA management.

string

Maximum length: 15

dst

Default route destination for reserved HA management interface.

ipv4-classnet

Not Specified

gateway

Default route gateway for reserved HA management interface.

ipv4-address

Not Specified

gateway6

Default IPv6 gateway for reserved HA management interface.

ipv6-address

Not Specified

config system ha

Configure HA.

config system ha
    Description: Configure HA.
    set group-id {integer}
    set group-name {string}
    set mode [standalone|config-sync-only|...]
    set password {password}
    set key {password}
    set hbdev {user}
    set unicast-hb [enable|disable]
    set unicast-hb-peerip {ipv4-address}
    set unicast-hb-netmask {ipv4-netmask}
    set encryption [enable|disable]
    set authentication [enable|disable]
    set hb-interval {integer}
    set hb-lost-threshold {integer}
    set hello-holddown {integer}
    set gratuitous-arps [enable|disable]
    set arps {integer}
    set arps-interval {integer}
    set link-failed-signal [enable|disable]
    set uninterruptible-upgrade [enable|disable]
    set sequential-upgrade [enable|disable]
    set ha-mgmt-status [enable|disable]
    config ha-mgmt-interfaces
        Description: Reserve interfaces to manage individual cluster units.
        edit <id>
            set interface {string}
            set dst {ipv4-classnet}
            set gateway {ipv4-address}
            set gateway6 {ipv6-address}
        next
    end
    set ha-uptime-diff-margin {integer}
    set ha-direct [enable|disable]
    set vcluster-id {integer}
    set override [enable|disable]
    set priority {integer}
    set override-wait-time {integer}
    set monitor {string}
    set memory-compatible-mode [enable|disable]
end

config system ha

Parameter

Description

Type

Size

group-id

Cluster group ID . Must be the same for all members.

integer

Minimum value: 0 Maximum value: 255

group-name

Cluster group name. Must be the same for all members.

string

Maximum length: 32

mode

HA mode. Must be the same for all members. FGSP requires standalone.

option

-

Option

Description

standalone

Disable HA feature.

config-sync-only

Enable Config sync only

active-passive

Enable Active-passive mode.

password

Cluster password. Must be the same for all members.

password

Not Specified

key

key

password

Not Specified

hbdev

Heartbeat interfaces. Must be the same for all members.

user

Not Specified

unicast-hb

Enable/disable unicast heartbeat.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

unicast-hb-peerip

Unicast heartbeat peer IP.

ipv4-address

Not Specified

unicast-hb-netmask

Unicast heartbeat netmask.

ipv4-netmask

Not Specified

encryption

Enable/disable heartbeat message encryption.

option

-

Option

Description

enable

Enable heartbeat message encryption.

disable

Disable heartbeat message encryption.

authentication

Enable/disable heartbeat message authentication.

option

-

Option

Description

enable

Enable heartbeat message authentication.

disable

Disable heartbeat message authentication.

hb-interval

Time between sending heartbeat packets . Increase to reduce false positives.

integer

Minimum value: 1 Maximum value: 20

hb-lost-threshold

Number of lost heartbeats to signal a failure . Increase to reduce false positives.

integer

Minimum value: 1 Maximum value: 60

hello-holddown

Time to wait before changing from hello to work state .

integer

Minimum value: 5 Maximum value: 300

gratuitous-arps

Enable/disable gratuitous ARPs. Disable if link-failed-signal enabled.

option

-

Option

Description

enable

Enable gratuitous ARPs.

disable

Disable gratuitous ARPs.

arps

Number of gratuitous ARPs . Lower to reduce traffic. Higher to reduce failover time.

integer

Minimum value: 1 Maximum value: 60

arps-interval

Time between gratuitous ARPs . Lower to reduce failover time. Higher to reduce traffic.

integer

Minimum value: 1 Maximum value: 20

link-failed-signal

Enable to shut down all interfaces for 1 sec after a failover. Use if gratuitous ARPs do not update network.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

uninterruptible-upgrade

Enable to upgrade a cluster without blocking network traffic.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

sequential-upgrade

Enable to upgrade secondaries one by one.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

ha-mgmt-status

Enable to reserve interfaces to manage individual cluster units.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

ha-uptime-diff-margin

Normally you would only reduce this value for failover testing.

integer

Minimum value: 1 Maximum value: 65535

ha-direct

Enable/disable using ha-mgmt interface for syslog, SNMP, remote authentication (RADIUS), FortiAnalyzer, FortiManager and FortiSandbox.

option

-

Option

Description

enable

Enable using ha-mgmt interface for syslog, SNMP, remote authentication (RADIUS), FortiAnalyzer, FortiManager and FortiSandbox.

disable

Disable using ha-mgmt interface for syslog, SNMP, remote authentication (RADIUS), FortiAnalyzer, FortiManager and FortiSandbox.

vcluster-id

Cluster ID.

integer

Minimum value: 0 Maximum value: 255

override

Enable and increase the priority of the unit that should always be primary.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

priority

Increase the priority to select the primary unit .

integer

Minimum value: 0 Maximum value: 255

override-wait-time

Delay negotiating if override is enabled . Reduces how often the cluster negotiates.

integer

Minimum value: 0 Maximum value: 3600

monitor

Interfaces to check for port monitoring (or link failure).

string

Maximum length: 19

memory-compatible-mode

Enable/disable memory compatible mode.

option

-

Option

Description

enable

Enable setting.

disable

Disable setting.

config ha-mgmt-interfaces

Parameter

Description

Type

Size

interface

Interface to reserve for HA management.

string

Maximum length: 15

dst

Default route destination for reserved HA management interface.

ipv4-classnet

Not Specified

gateway

Default route gateway for reserved HA management interface.

ipv4-address

Not Specified

gateway6

Default IPv6 gateway for reserved HA management interface.

ipv6-address

Not Specified