FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Not applicable
Article Id 190718
Article
Errata

The definition of age in all HA documentation before FortiOS v3.0 MR5 was incorrect. The correct definition of Age is below. This new definition will be in all FortiGate HA documentation released after MR5.

Documentation Affected
  • FortiGate v2.80 and v3.0 HA Overview for all MRs up to and including MR4 (the MR4 document number is 01-30004-0351-20070208)
  • FortiGate v2.80 and v3.0 HA Guide for all MRs up to and including MR3 (the MR3 document number is 01-30003-0112-20061020)
Corrected Text

Age

The cluster unit with the highest age value becomes the primary unit. The age of a cluster unit is the amount of time since a monitored interface failed (is disconnected or stops operating). Age is also reset when a cluster unit starts. So, when all cluster units start up at the same time, they all have the same age. So age does not affect primary unit selection when all cluster units start up at the same time.

If a link failure of a monitored interface occurs, the age value for the cluster unit that experiences the link failure is reset. This cluster unit will have a lower age than the other units in the cluster. Because of the link failure, this reduced age value will not normally have an effect on primary unit negotiation.

If all monitored interface links are restored the cluster unit could potentially become the primary unit. However, because the cluster unit age was reset when the link failed, the cluster unit with the restored link has a lower age than all other cluster units and cannot become the primary unit. As a result, the age reduces the number of times the cluster negotiates and selects a new primary unit.

Note: In any cluster, some of the FortiGate units in the cluster may take longer to start up than others. This startup time difference can happen as a result of a number of issues and does not affect the normal operation of the cluster. To make sure that cluster units that start slower can still become primary units, the FGCP ignores age differences of up to 5 minutes.

Release(d) DateThis change will appear in the FortiOS v3.0 MR5 HA documentation.