86 Fortinet Inc.
Managing the HA cluster High availabili ty

Starting the HA cluster

After all of the FortiGate units in the cluster are configured for HA and once the cluster
is connected, use the following procedure to start the HA cluster.
1Power on all of the HA units in the cluster.
As the units power on they negotiate to choose the primary cluster unit and the
subordinate units. This negotiation occurs with no user intervention.
When negotiation is complete the cluster is ready to begin processing network traffic.
You can use the information in “Managing the HA cluster” on page86 to log into and
manage the cluster.
Managing the HA cluster
When a FortiGate cluster is up and running, you manage it as a cluster instead of a
group of individual FortiGate units. You manage the cluster by connecting to the
web-based manager or CLI using any interface configured for management access.
Since all units in the cluster are configured with the same interface IP addresses
(except for the HA interface), connecting to any interface IP address configured for
management access connects to that cluster interface; which automatically connects
you to the primary FortiGate unit.
You can also connect to and manage individual units in the cluster by connecting to
their HA interfaces (all of which are configured with a different IP address).
You can also manage individual cluster units by connect to the primary unit CLI. From
here you can use the execute ha manage command to connect to the CLI of each
unit in the cluster.
This section describes:
Viewing the status of cluster members
Monitoring cluster members
Monitoring cluster sessions
Viewing and managing cluster log messages
Managing individual cluster units
Synchronizing the cluster configuration
Returning to standalone configuration
Replacing a FortiGate unit after fail-over

Viewing the status of cluster members

To view the status of each cluster member.
1Connect to the cluster and log into the web-based manager.
2Go to System > Status > Cluster Members.
The web-based manager lists the serial numbers of all of the FortiGate units in the
cluster. The primary unit is identified as Local. For each cluster member, the list
includes the up time and status for that cluster member.