{"id":1323,"date":"2026-09-08T21:25:23","date_gmt":"2026-09-08T15:55:23","guid":{"rendered":"https:\/\/networkfix.in\/uncategorized\/fortigate-high-availability-active-passive-configuration-and-failover\/"},"modified":"2026-09-14T04:34:34","modified_gmt":"2026-09-13T23:04:34","slug":"fortigate-high-availability-active-passive-configuration-and-failover","status":"publish","type":"post","link":"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/fortigate-high-availability-active-passive-configuration-and-failover\/","title":{"rendered":"FortiGate High Availability Active-Passive Configuration and Failover Testing"},"content":{"rendered":"<p>Deploying a <strong>FortiGate HA active passive configuration<\/strong> ensures enterprise networks maintain continuous operations during hardware, cable, or link failures. Fortinet uses the FortiGate Clustering Protocol (FGCP) to manage cluster state, synchronize firewall sessions, and coordinate failover events. In an Active-Passive high availability deployment, one unit actively processes all network traffic while the standby unit continuously synchronizes configuration and session states. If the primary firewall fails, the secondary firewall assumes the active role within milliseconds, preventing service disruptions.<\/p>\n<p>This technical guide details how to plan, build, verify, and test a high-availability active-passive cluster on FortiGate firewalls running FortiOS. You will learn the exact election mechanics, session synchronization principles, CLI and GUI setup procedures, and practical troubleshooting workflows necessary for production readiness.<\/p>\n<h2>Real-Life Scenario<\/h2>\n<p>An enterprise organization requires zero-downtime architecture for its primary datacenter. The network team is deploying two identical FortiGate appliances to protect critical internal services, web applications, and database infrastructure. The primary business requirements for this cluster include:<\/p>\n<ul>\n<li>Automatic failover of all perimeter traffic without breaking active TCP sessions.<\/li>\n<li>Interface monitoring on primary WAN and LAN links to trigger cluster failover if an upstream or downstream link drops.<\/li>\n<li>Dedicated redundant heartbeat links to prevent split-brain conditions.<\/li>\n<li>In-band or dedicated out-of-band management access to both firewall nodes individually for maintenance.<\/li>\n<\/ul>\n<h2>Lab Topology<\/h2>\n<p>The topology consists of two FortiGate appliances (FGT-A and FGT-B) linked together through dual dedicated heartbeat interfaces. Both units connect to redundant Layer 2 switches on the WAN and LAN sides.<\/p>\n<pre>\n                      +-------------------+\n                      |   Upstream WAN    |\n                      |   L2\/L3 Switch    |\n                      +---------+---------+\n                                |\n               +----------------+----------------+\n               |                                 |\n        (port1 | 198.51.100.10)           (port1 | 198.51.100.10)\n        +------+------+                   +------+------+\n        |             |   hb1 (port5)     |             |\n        |  FortiGate  +-------------------+  FortiGate  |\n        |    FGT-A    |                   |    FGT-B    |\n        |  (Primary)  +-------------------+ (Secondary) |\n        |             |   hb2 (port6)     |             |\n        +------+------+                   +------+------+\n        (port2 | 192.0.2.1)               (port2 | 192.0.2.1)\n               |                                 |\n               +----------------+----------------+\n                                |\n                      +---------+---------+\n                      |    Internal     |\n                      |   LAN Switch    |\n                      +-------------------+\n<\/pre>\n<h2>Example Addressing and Objects<\/h2>\n<p>The following table lists the IP addressing, interface assignments, and system roles used throughout this guide. These values represent a lab environment and must be adapted to match your production environment.<\/p>\n<table>\n<thead>\n<tr>\n<th>Device Hostname<\/th>\n<th>Interface<\/th>\n<th>Role \/ Connection<\/th>\n<th>Example IP \/ Subnet<\/th>\n<th>HA Configuration Parameter<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>FGT-A (Node 1)<\/td>\n<td>port1<\/td>\n<td>External \/ WAN<\/td>\n<td>198.51.100.10\/24<\/td>\n<td>Monitored Interface<\/td>\n<\/tr>\n<tr>\n<td>FGT-A (Node 1)<\/td>\n<td>port2<\/td>\n<td>Internal \/ LAN<\/td>\n<td>192.0.2.1\/24<\/td>\n<td>Monitored Interface<\/td>\n<\/tr>\n<tr>\n<td>FGT-A (Node 1)<\/td>\n<td>port5, port6<\/td>\n<td>Dedicated Heartbeat<\/td>\n<td>Unnumbered (FGCP internal)<\/td>\n<td>Heartbeat Interfaces (Priority 50)<\/td>\n<\/tr>\n<tr>\n<td>FGT-A (Node 1)<\/td>\n<td>mgmt1<\/td>\n<td>Out-of-Band Mgmt<\/td>\n<td>203.0.113.11\/24<\/td>\n<td>Reserved Management Interface<\/td>\n<\/tr>\n<tr>\n<td>FGT-B (Node 2)<\/td>\n<td>port1<\/td>\n<td>External \/ WAN<\/td>\n<td>198.51.100.10\/24<\/td>\n<td>Monitored Interface<\/td>\n<\/tr>\n<tr>\n<td>FGT-B (Node 2)<\/td>\n<td>port2<\/td>\n<td>Internal \/ LAN<\/td>\n<td>192.0.2.1\/24<\/td>\n<td>Monitored Interface<\/td>\n<\/tr>\n<tr>\n<td>FGT-B (Node 2)<\/td>\n<td>port5, port6<\/td>\n<td>Dedicated Heartbeat<\/td>\n<td>Unnumbered (FGCP internal)<\/td>\n<td>Heartbeat Interfaces (Priority 50)<\/td>\n<\/tr>\n<tr>\n<td>FGT-B (Node 2)<\/td>\n<td>mgmt1<\/td>\n<td>Out-of-Band Mgmt<\/td>\n<td>203.0.113.12\/24<\/td>\n<td>Reserved Management Interface<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Prerequisites<\/h2>\n<p>Before configuring FGCP Active-Passive High Availability, verify that both FortiGate appliances meet the following mandatory requirements:<\/p>\n<ul>\n<li><strong>Identical Hardware Model:<\/strong> Both devices must be the exact same hardware model and revision (for example, two FortiGate-100F units). High availability across different models is not supported.<\/li>\n<li><strong>Matching Firmware Version:<\/strong> Both units must run the exact same FortiOS release, including major, minor, and patch levels.<\/li>\n<li><strong>Identical Hardware Storage:<\/strong> Storage configurations must match. If one unit has an internal SSD installed, the secondary unit must have the same drive configuration.<\/li>\n<li><strong>Licensing Alignment:<\/strong> System licenses (FortiCare, UTM\/FortiGuard contracts, Virtual Domain limits) should match. Mismatched subscription services cause feature degradation or synchronization warnings.<\/li>\n<li><strong>Direct Physical Connections:<\/strong> Connect at least two dedicated physical interfaces directly between the appliances using patch cables for heartbeat redundancy. Do not route heartbeat traffic through unmanaged or shared intermediate switches without dedicated VLAN isolation.<\/li>\n<\/ul>\n<h2>Step-by-Step GUI Configuration<\/h2>\n<p><em>Note: FortiOS GUI menu structures can vary slightly between major releases. The steps below reflect standard FortiOS v7.x navigation.<\/em><\/p>\n<h3>Step 1: Configure the Primary Firewall (FGT-A)<\/h3>\n<ol>\n<li>Log into the web-based manager of the primary FortiGate unit.<\/li>\n<li>Navigate to <strong>System &gt; HA<\/strong>.<\/li>\n<li>Set the <strong>Mode<\/strong> to <strong>Active-Passive<\/strong>.<\/li>\n<li>Enter a <strong>Device Priority<\/strong> of <code>200<\/code> (higher values increase the likelihood of selection as primary during initial cluster formation).<\/li>\n<li>Enter a <strong>Group Name<\/strong> (for example, <code>DC-HA-CLUSTER<\/code>).<\/li>\n<li>Set a unique <strong>Group ID<\/strong> integer between <code>1<\/code> and <code>255<\/code> (for example, <code>50<\/code>). This ID prevents Virtual MAC collisions if multiple FortiGate clusters share the same Layer 2 switch environment.<\/li>\n<li>Under <strong>Heartbeat Interfaces<\/strong>, click <strong>+<\/strong> and select <code>port5<\/code> and <code>port6<\/code>. Assign a heartbeat priority (for example, <code>50<\/code>).<\/li>\n<li>Under <strong>Monitored Interfaces<\/strong>, select your active data interfaces: <code>port1<\/code> (WAN) and <code>port2<\/code> (LAN).<\/li>\n<li>Click <strong>Apply<\/strong>.<\/li>\n<\/ol>\n<h3>Step 2: Configure the Secondary Firewall (FGT-B)<\/h3>\n<ol>\n<li>Log into the web-based manager of the secondary unit before connecting the data cables.<\/li>\n<li>Navigate to <strong>System &gt; HA<\/strong>.<\/li>\n<li>Set the <strong>Mode<\/strong> to <strong>Active-Passive<\/strong>.<\/li>\n<li>Set a lower <strong>Device Priority<\/strong> of <code>100<\/code>.<\/li>\n<li>Specify the exact same <strong>Group Name<\/strong> (<code>DC-HA-CLUSTER<\/code>) and <strong>Group ID<\/strong> (<code>50<\/code>).<\/li>\n<li>Select the exact same <strong>Heartbeat Interfaces<\/strong> (<code>port5<\/code> and <code>port6<\/code>).<\/li>\n<li>Select the exact same <strong>Monitored Interfaces<\/strong> (<code>port1<\/code> and <code>port2<\/code>).<\/li>\n<li>Click <strong>Apply<\/strong>.<\/li>\n<\/ol>\n<p>Once you apply the settings on the secondary firewall and connect the heartbeat cables, FGT-B connects to FGT-A via FGCP, performs an initial configuration synchronization, and assumes the secondary status.<\/p>\n<h2>Executing the FortiGate HA Active Passive Configuration via CLI<\/h2>\n<p>The command line provides the precise, deterministic method for establishing an HA cluster. The configuration must be performed on each unit individually before they form the cluster.<\/p>\n<h3>Primary Firewall (FGT-A) CLI Setup<\/h3>\n<pre><code>config system ha\n    set mode a-p\n    set group-id 50\n    set group-name \"DC-HA-CLUSTER\"\n    set priority 200\n    set override disable\n    set hbdev \"port5\" 50 \"port6\" 50\n    set monitor \"port1\" \"port2\"\n    set ha-mgmt-status enable\n    config ha-mgmt-interfaces\n        edit 1\n            set interface \"mgmt1\"\n            set gateway 203.0.113.1\n        next\n    end\nend\n<\/code><\/pre>\n<h3>Secondary Firewall (FGT-B) CLI Setup<\/h3>\n<pre><code>config system ha\n    set mode a-p\n    set group-id 50\n    set group-name \"DC-HA-CLUSTER\"\n    set priority 100\n    set override disable\n    set hbdev \"port5\" 50 \"port6\" 50\n    set monitor \"port1\" \"port2\"\n    set ha-mgmt-status enable\n    config ha-mgmt-interfaces\n        edit 1\n            set interface \"mgmt1\"\n            set gateway 203.0.113.1\n        next\n    end\nend\n<\/code><\/pre>\n<h3>Why These Commands Are Required<\/h3>\n<ul>\n<li><code>set mode a-p<\/code>: Defines the cluster operation as Active-Passive.<\/li>\n<li><code>set group-id 50<\/code>: Calculates the Virtual MAC (VMAC) offset for cluster interfaces to prevent MAC address duplicates across local Layer 2 broadcast domains.<\/li>\n<li><code>set priority<\/code>: Assigns the node weighting for cluster negotiation. The unit with the highest priority becomes the primary node if all other conditions match.<\/li>\n<li><code>set override disable<\/code>: Disables automatic primary unit failback when a failed unit with a higher priority boots back up. Keeping this disabled prevents unnecessary traffic interruptions caused by secondary failbacks.<\/li>\n<li><code>set hbdev<\/code>: Identifies dedicated physical interfaces for cluster communication, heartbeat checks, and state synchronization.<\/li>\n<li><code>set monitor<\/code>: Enables continuous link-state detection on critical interfaces. If a monitored link goes down, the primary node reduces its internal score to force a failover to the secondary node.<\/li>\n<li><code>set ha-mgmt-status enable<\/code>: Isolates administrative management traffic onto dedicated management interfaces (`mgmt1`), allowing administrators to SSH or connect to the GUI of both physical appliances independently.<\/li>\n<\/ul>\n<h2>How the Traffic Flows<\/h2>\n<p>Understanding packet processing within an Active-Passive FGCP cluster clarifies how session persistence and virtual addressing operate behind the scenes.<\/p>\n<h3>Virtual MAC (VMAC) Allocation<\/h3>\n<p>In an Active-Passive deployment, the primary unit takes ownership of virtual IP addresses on all active data interfaces. To avoid waiting for standard ARP timeouts across connected Layer 2 switches during a failover event, FGCP assigns a Virtual MAC address to each cluster data interface.<\/p>\n<p>The standard FGCP VMAC address format is:<\/p>\n<pre><code>00-09-0f-09-&lt;group-id-hex&gt;-&lt;interface-index-hex&gt;<\/code><\/pre>\n<p>For example, with a Group ID of 50 (0x32 in hexadecimal), all cluster data interfaces receive a MAC starting with <code>00-09-0f-09-32-xx<\/code>. Downstream switches learn this VMAC on the switch port connected to the primary firewall. The secondary firewall keeps its physical data ports active at Layer 1, but drops all inbound and outbound data traffic at Layer 2.<\/p>\n<h3>Session Synchronization<\/h3>\n<p>When client traffic matches a firewall policy on the primary unit, FortiOS writes the connection state into its local session table. By default, FGCP synchronizes stateful TCP connections across the dedicated heartbeat links (`hbdev`) to the secondary unit.<\/p>\n<p>During normal operations:<\/p>\n<ol>\n<li>Client sends TCP SYN to the primary unit.<\/li>\n<li>Primary unit processes the packet, creates a session table entry, and transmits a synchronization packet across the heartbeat link to the secondary unit.<\/li>\n<li>The secondary unit updates its kernel session mirror.<\/li>\n<li>If a hardware failure occurs on the primary, the secondary assumes the primary role, broadcasts a gratuitous ARP containing the VMAC, and immediately processes ongoing TCP connections without requiring clients to re-establish sessions.<\/li>\n<\/ol>\n<p><em>Note: UDP, ICMP, and certain non-stateful application sessions are generally not synchronized by default unless explicit session sync settings are applied.<\/em><\/p>\n<h2>Verification<\/h2>\n<p>After completing the configuration and connecting the heartbeat cables, verify cluster operation using diagnostic CLI commands.<\/p>\n<h3>Check Cluster Status<\/h3>\n<p>Execute the following command on either unit:<\/p>\n<pre><code>get system ha status<\/code><\/pre>\n<p>Look for the following key indicators in the output:<\/p>\n<ul>\n<li><strong>Cluster Model:<\/strong> Matches your appliance hardware model.<\/li>\n<li><strong>Health Status:<\/strong> Displays OK for both heartbeat links.<\/li>\n<li><strong>Master\/Primary Node:<\/strong> Displays the unit with the higher priority (e.g., FGT-A).<\/li>\n<li><strong>Slave\/Secondary Node:<\/strong> Lists the peer unit (e.g., FGT-B) with state marked as <code>in-sync<\/code>.<\/li>\n<\/ul>\n<p>Example command output:<\/p>\n<pre><code>HA Health Status: OK\nModel: FortiGate-100F\nMode: Active-Passive\nGroup: 50\nDebug: 0\nCluster Uptime: 3 days 04:12:30\nCluster state change time: 2023-10-24 10:15:00\nMaster selected reason: priority\nPrimary : FGT-A , FG100FTK21000001, HA cluster index = 0\nSecondary : FGT-B , FG100FTK21000002, HA cluster index = 1\nSystem Configuration sync status: in-sync\n<\/code><\/pre>\n<h3>Verify Checksum Synchronization<\/h3>\n<p>To confirm that both appliances share identical configurations, execute:<\/p>\n<pre><code>diagnose sys ha checksum cluster<\/code><\/pre>\n<p>The command outputs checksum strings for both appliances. If the configuration is fully synchronized, the total global checksum and debug zone checksum values match across all cluster members:<\/p>\n<pre><code>================== Debug State Checksum ==================\nis_master: 1\nnode: 0, serial: FG100FTK21000001, checksum: e4d2a1c09f3b8a1e\nnode: 1, serial: FG100FTK21000002, checksum: e4d2a1c09f3b8a1e\n<\/code><\/pre>\n<h3>Failover Testing<\/h3>\n<p>Execute a controlled failover test during an approved maintenance window to validate performance:<\/p>\n<ol>\n<li>Start a continuous ping from an internal host (192.0.2.100) to an external resource (198.51.100.1).<\/li>\n<li>Disconnect the primary WAN cable (<code>port1<\/code>) on FGT-A.<\/li>\n<li>Observe the continuous ping. Failover should complete within 1 to 2 packet drops.<\/li>\n<li>Check the HA cluster status on FGT-B using <code>get system ha status<\/code>. FGT-B should report itself as the primary unit due to port monitoring on FGT-A detecting a link drop.<\/li>\n<li>Reconnect <code>port1<\/code> on FGT-A. Because <code>override<\/code> is set to <code>disable<\/code>, FGT-B remains the primary firewall, preventing an unnecessary second failover.<\/li>\n<\/ol>\n<h2>Troubleshooting<\/h2>\n<p>If an active-passive cluster behaves unexpectedly, use the structured troubleshooting workflow below.<\/p>\n<h3>1. Configuration Mismatch (OutOfSync State)<\/h3>\n<p><strong>Symptom:<\/strong> System HA status displays secondary status as <code>out-of-sync<\/code> or checksums do not match.<\/p>\n<p><strong>Verification Commands:<\/strong><\/p>\n<pre><code>diagnose sys ha checksum show<\/code><\/pre>\n<p>To force the secondary unit to re-synchronize its configuration database from the primary unit, execute this command on the secondary firewall:<\/p>\n<pre><code>execute ha recalculate-checksum<\/code><\/pre>\n<h3>2. Split-Brain Condition<\/h3>\n<p><strong>Symptom:<\/strong> Both FortiGate units claim to be the primary master simultaneously, causing massive packet loss and IP collisions.<\/p>\n<p><strong>Likely Cause:<\/strong> Loss of all heartbeat connectivity between units (e.g., disconnected cables, misconfigured VLANs, or dead ports).<\/p>\n<p><strong>Verification:<\/strong> Check physical interface states on <code>port5<\/code> and <code>port6<\/code>. Ensure heartbeat interfaces are plugged in directly and not passing through an unconfigured intermediate switch.<\/p>\n<h3>3. Real-Time Debugging<\/h3>\n<p><strong style=\"color: #c0392b\">CAUTION:<\/strong> Running real-time debug commands on high-volume production firewalls can increase CPU utilization. Run debugs only when necessary and ensure you stop the process when finished.<\/p>\n<p>To inspect heartbeat communication and HA state daemon messages in real time, run:<\/p>\n<pre><code>diagnose debug application hatalk -1\ndiagnose debug enable\n<\/code><\/pre>\n<p>After collecting diagnostic output, safely disable debug logging by executing:<\/p>\n<pre><code>diagnose debug disable\ndiagnose debug reset\n<\/code><\/pre>\n<h2>Common Mistakes<\/h2>\n<ul>\n<li><strong>Forgetting to Set a Unique Group ID:<\/strong> If two separate HA pairs exist on the same Layer 2 switch topology using the default Group ID of <code>0<\/code>, both clusters generate identical Virtual MAC addresses, leading to severe network flapping.<\/li>\n<li><strong>Enabling Auto-Override Unintentionally:<\/strong> Setting <code>set override enable<\/code> causes the cluster to fail back to a higher-priority device the moment it reboots. If that device has an underlying hardware fault, the network will loop through continuous failover states (flapping).<\/li>\n<li><strong>Monitoring Heartbeat Interfaces:<\/strong> Do not add heartbeat links (`port5`, `port6`) into the <code>set monitor<\/code> list. Only data plane interfaces (WAN, LAN, DMZ) should be monitored.<\/li>\n<li><strong>Using Unreliable Intermediate Switches for Heartbeats:<\/strong> Running heartbeat traffic through unmanaged third-party switches introduces single points of failure and packet delays that can cause unnecessary failovers.<\/li>\n<li><strong>Mismatched Hardware or Modules:<\/strong> Attempting to build an HA pair using nodes with different RAM configurations, transceivers, or disk layouts will result in cluster failure or unsynchronized states.<\/li>\n<\/ul>\n<h2>Production Considerations<\/h2>\n<p>When preparing an Active-Passive FortiGate cluster for production environments, review the following operational best practices:<\/p>\n<h3>1. Rolling Firmware Upgrades<\/h3>\n<p>FGCP supports zero-downtime firmware upgrades. When an upgrade is initiated from the primary unit, FortiOS automatically uploads the firmware image to the secondary unit first. The secondary unit updates, reboots, and assumes the primary role. The former primary unit then updates, reboots, and rejoins the cluster as the new secondary unit.<\/p>\n<h3>2. Session Synchronization Tuning<\/h3>\n<p>While session sync is vital for stateful connections, high-volume transactional traffic (such as rapid short-lived DNS or HTTP queries) can exhaust heartbeat bandwidth. Consider tuning performance or excluding non-critical connection types if heartbeat links experience high utilization.<\/p>\n<h3>3. Dedicated Out-of-Band Management<\/h3>\n<p>Always configure <code>ha-mgmt-interfaces<\/code>. Reserving dedicated management ports (e.g., <code>mgmt1<\/code>) with distinct IP addresses allows your monitoring systems (SNMP, Syslog, FortiAnalyzer) to poll each firewall node independently, regardless of which unit is currently active.<\/p>\n<h2>Related FortiGate Guides<\/h2>\n<ul>\n<li><a href=\"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/fortigate-sd-wan-configuration-for-dual-isp-failover-and-load-balancin\/\">FortiGate SD-WAN configuration<\/a><\/li>\n<li><a href=\"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/fortigate-session-troubleshooting-with-flow-debug-sessions-and-logs\/\">FortiGate session troubleshooting<\/a><\/li>\n<li><a href=\"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/fortigate-packet-sniffer-and-debug-flow-for-real-troubleshooting\/\">FortiGate packet sniffer and debug flow<\/a><\/li>\n<li><a href=\"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/fortigate-ldap-authentication-with-active-directory-configuration-and\/\">FortiGate LDAP with Active Directory<\/a><\/li>\n<\/ul>\n<h2>Summary<\/h2>\n<p>A proper <strong>FortiGate HA active passive configuration<\/strong> provides high-availability network protection for mission-critical enterprise environments. By configuring dedicated heartbeat interfaces, enforcing explicit group IDs, setting up monitored data interfaces, and adhering to strict firmware matching, network administrators can deploy a resilient cluster capable of handling hardware and link outages seamlessly.<\/p>","protected":false},"excerpt":{"rendered":"<p>Learn FortiGate HA active passive configuration with a practical real-life example, step-by-step configuration, verification and troubleshooting.<\/p>","protected":false},"author":2,"featured_media":1326,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","rank_math_title":"","rank_math_description":"","rank_math_focus_keyword":"","_dpc-meta-title":"","_dpc-meta-description":"","_dpc-keyword":""},"categories":[4],"tags":[137,29,41,146,44,43,147],"class_list":["post-1323","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-fortinet","tag-advanced","tag-firewall-tutorial","tag-fortigate","tag-fortigate-ha-active-passive-configuration","tag-fortinet","tag-fortios","tag-high-availability"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.2 (Yoast SEO v28.6) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>FortiGate High Availability Active-Passive Configuration...<\/title>\n<meta name=\"description\" content=\"Learn FortiGate HA active passive configuration with a practical real-life example, step-by-step configuration, verification and troubleshooting.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/fortigate-high-availability-active-passive-configuration-and-failover\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"FortiGate High Availability Active-Passive Configuration and Failover Testing\" \/>\n<meta property=\"og:description\" content=\"Learn FortiGate HA active passive configuration with a practical real-life example, step-by-step configuration, verification and troubleshooting.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/fortigate-high-availability-active-passive-configuration-and-failover\/\" \/>\n<meta property=\"og:site_name\" content=\"NetworkFix\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-08T15:55:23+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-13T23:04:34+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/fortigate-high-availability-active-passive-firewall-pair-and.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"1376\" \/>\n\t<meta property=\"og:image:height\" content=\"768\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Ajay Yadav\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Ajay Yadav\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"11 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-high-availability-active-passive-configuration-and-failover\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-high-availability-active-passive-configuration-and-failover\\\/\"},\"author\":{\"name\":\"Ajay Yadav\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/dac05d268c126277e74b684c5239d344\"},\"headline\":\"FortiGate High Availability Active-Passive Configuration and Failover Testing\",\"datePublished\":\"2026-09-08T15:55:23+00:00\",\"dateModified\":\"2026-09-13T23:04:34+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-high-availability-active-passive-configuration-and-failover\\\/\"},\"wordCount\":1921,\"publisher\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\"},\"image\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-high-availability-active-passive-configuration-and-failover\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/fortigate-high-availability-active-passive-firewall-pair-and.jpeg\",\"keywords\":[\"Advanced\",\"Firewall Tutorial\",\"FortiGate\",\"FortiGate HA active passive configuration\",\"Fortinet\",\"FortiOS\",\"High Availability\"],\"articleSection\":[\"FortiGate\"],\"inLanguage\":\"en\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-high-availability-active-passive-configuration-and-failover\\\/\",\"url\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-high-availability-active-passive-configuration-and-failover\\\/\",\"name\":\"FortiGate High Availability Active-Passive Configuration...\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-high-availability-active-passive-configuration-and-failover\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-high-availability-active-passive-configuration-and-failover\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/fortigate-high-availability-active-passive-firewall-pair-and.jpeg\",\"datePublished\":\"2026-09-08T15:55:23+00:00\",\"dateModified\":\"2026-09-13T23:04:34+00:00\",\"description\":\"Learn FortiGate HA active passive configuration with a practical real-life example, step-by-step configuration, verification and troubleshooting.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-high-availability-active-passive-configuration-and-failover\\\/#breadcrumb\"},\"inLanguage\":\"en\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-high-availability-active-passive-configuration-and-failover\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-high-availability-active-passive-configuration-and-failover\\\/#primaryimage\",\"url\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/fortigate-high-availability-active-passive-firewall-pair-and.jpeg\",\"contentUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/fortigate-high-availability-active-passive-firewall-pair-and.jpeg\",\"width\":1376,\"height\":768,\"caption\":\"FortiGate high availability active-passive firewall pair and failover testing\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/tutorials\\\/fortinet\\\/fortigate-high-availability-active-passive-configuration-and-failover\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/networkfix.in\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"FortiGate High Availability Active-Passive Configuration and Failover Testing\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#website\",\"url\":\"https:\\\/\\\/networkfix.in\\\/\",\"name\":\"NetworkFix\",\"description\":\"Practical Network Security &amp; Firewall Guides\",\"publisher\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/networkfix.in\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/28c6fb08b80eeae506b96250db4f30f0\",\"name\":\"networkfix\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"url\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"contentUrl\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\",\"width\":737,\"height\":591,\"caption\":\"networkfix\"},\"logo\":{\"@id\":\"https:\\\/\\\/networkfix.in\\\/wp-content\\\/uploads\\\/2026\\\/06\\\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png\"},\"sameAs\":[\"http:\\\/\\\/networkfix.in\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/networkfix.in\\\/#\\\/schema\\\/person\\\/dac05d268c126277e74b684c5239d344\",\"name\":\"Ajay Yadav\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g\",\"caption\":\"Ajay Yadav\"},\"url\":\"https:\\\/\\\/networkfix.in\\\/en\\\/author\\\/networkfix-news-bot\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"FortiGate High Availability Active-Passive Configuration...","description":"Learn FortiGate HA active passive configuration with a practical real-life example, step-by-step configuration, verification and troubleshooting.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/fortigate-high-availability-active-passive-configuration-and-failover\/","og_locale":"en_US","og_type":"article","og_title":"FortiGate High Availability Active-Passive Configuration and Failover Testing","og_description":"Learn FortiGate HA active passive configuration with a practical real-life example, step-by-step configuration, verification and troubleshooting.","og_url":"https:\/\/networkfix.in\/en\/tutorials\/fortinet\/fortigate-high-availability-active-passive-configuration-and-failover\/","og_site_name":"NetworkFix","article_published_time":"2026-09-08T15:55:23+00:00","article_modified_time":"2026-09-13T23:04:34+00:00","og_image":[{"width":1376,"height":768,"url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/fortigate-high-availability-active-passive-firewall-pair-and.jpeg","type":"image\/jpeg"}],"author":"Ajay Yadav","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Ajay Yadav","Est. reading time":"11 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-high-availability-active-passive-configuration-and-failover\/#article","isPartOf":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-high-availability-active-passive-configuration-and-failover\/"},"author":{"name":"Ajay Yadav","@id":"https:\/\/networkfix.in\/#\/schema\/person\/dac05d268c126277e74b684c5239d344"},"headline":"FortiGate High Availability Active-Passive Configuration and Failover Testing","datePublished":"2026-09-08T15:55:23+00:00","dateModified":"2026-09-13T23:04:34+00:00","mainEntityOfPage":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-high-availability-active-passive-configuration-and-failover\/"},"wordCount":1921,"publisher":{"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0"},"image":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-high-availability-active-passive-configuration-and-failover\/#primaryimage"},"thumbnailUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/fortigate-high-availability-active-passive-firewall-pair-and.jpeg","keywords":["Advanced","Firewall Tutorial","FortiGate","FortiGate HA active passive configuration","Fortinet","FortiOS","High Availability"],"articleSection":["FortiGate"],"inLanguage":"en"},{"@type":"WebPage","@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-high-availability-active-passive-configuration-and-failover\/","url":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-high-availability-active-passive-configuration-and-failover\/","name":"FortiGate High Availability Active-Passive Configuration...","isPartOf":{"@id":"https:\/\/networkfix.in\/#website"},"primaryImageOfPage":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-high-availability-active-passive-configuration-and-failover\/#primaryimage"},"image":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-high-availability-active-passive-configuration-and-failover\/#primaryimage"},"thumbnailUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/fortigate-high-availability-active-passive-firewall-pair-and.jpeg","datePublished":"2026-09-08T15:55:23+00:00","dateModified":"2026-09-13T23:04:34+00:00","description":"Learn FortiGate HA active passive configuration with a practical real-life example, step-by-step configuration, verification and troubleshooting.","breadcrumb":{"@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-high-availability-active-passive-configuration-and-failover\/#breadcrumb"},"inLanguage":"en","potentialAction":[{"@type":"ReadAction","target":["https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-high-availability-active-passive-configuration-and-failover\/"]}]},{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-high-availability-active-passive-configuration-and-failover\/#primaryimage","url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/fortigate-high-availability-active-passive-firewall-pair-and.jpeg","contentUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/09\/fortigate-high-availability-active-passive-firewall-pair-and.jpeg","width":1376,"height":768,"caption":"FortiGate high availability active-passive firewall pair and failover testing"},{"@type":"BreadcrumbList","@id":"https:\/\/networkfix.in\/tutorials\/fortinet\/fortigate-high-availability-active-passive-configuration-and-failover\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/networkfix.in\/"},{"@type":"ListItem","position":2,"name":"FortiGate High Availability Active-Passive Configuration and Failover Testing"}]},{"@type":"WebSite","@id":"https:\/\/networkfix.in\/#website","url":"https:\/\/networkfix.in\/","name":"NetworkFix","description":"Practical Network Security &amp; Firewall Guides","publisher":{"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/networkfix.in\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en"},{"@type":["Person","Organization"],"@id":"https:\/\/networkfix.in\/#\/schema\/person\/28c6fb08b80eeae506b96250db4f30f0","name":"networkfix","image":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","url":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","contentUrl":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png","width":737,"height":591,"caption":"networkfix"},"logo":{"@id":"https:\/\/mlwonxngeomz.i.optimole.com\/w:auto\/h:auto\/q:mauto\/f:best\/https:\/\/networkfix.in\/wp-content\/uploads\/2026\/06\/cropped-cc164cd4-f7b0-4c85-889e-8a89500fc258-2026-06-25.png"},"sameAs":["http:\/\/networkfix.in"]},{"@type":"Person","@id":"https:\/\/networkfix.in\/#\/schema\/person\/dac05d268c126277e74b684c5239d344","name":"Ajay Yadav","image":{"@type":"ImageObject","inLanguage":"en","@id":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/54c192b947be1e6f455c98ef8939f3bb3eb1a73fc8fd2814579cf29f4c581518?s=96&d=mm&r=g","caption":"Ajay Yadav"},"url":"https:\/\/networkfix.in\/en\/author\/networkfix-news-bot\/"}]}},"_links":{"self":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/1323","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/comments?post=1323"}],"version-history":[{"count":2,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/1323\/revisions"}],"predecessor-version":[{"id":1573,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/posts\/1323\/revisions\/1573"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/media\/1326"}],"wp:attachment":[{"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/media?parent=1323"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/categories?post=1323"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/networkfix.in\/en\/wp-json\/wp\/v2\/tags?post=1323"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}