← Back to knowledge base
medium

Troubleshooting a FortiGate HA cluster join failure caused by a password mismatch

Confirmed 8/8/2026

Problem

A FortiGate does not join the HA cluster because the HA password configured on the primary and secondary firewalls does not match.

Symptoms

The FortiGate remains outside the HA cluster. HA debug output can indicate an HA password mismatch.

Environment

FortiGate HA clusters; all FortiGate models and versions.

FortiOS version

All versions

Root Cause

The HA password differs between the primary and secondary FortiGate units.

Solution

  1. Enable HA communication and synchronization debugging to determine why the FortiGate is not joining the cluster:
diagnose debug application hatalk -1
diagnose debug application hasync -1
diagnose debug console timestamp enable
diagnose debug enable
  1. Review the debug output for an HA password mismatch.

  2. Disable debugging after collecting the required output:

diagnose debug disable
  1. Configure the correct HA password on the primary or secondary FortiGate. The password must be identical on both units:
config system ha
    set password "ha_password"
end
  1. Allow the FortiGate to join the HA cluster after the matching password is configured.

Verification

Confirm that the FortiGate joins the HA cluster after both the primary and secondary firewalls use the same HA password.

Tags

No tags yet.

Community rating

— / 5 (0)

Discussion (0)

    No comments yet.