medium
Troubleshooting a FortiGate HA cluster join failure caused by a password mismatch
Confirmed 8/8/2026
Problem
A FortiGate does not join the HA cluster because the HA password configured on the primary and secondary firewalls does not match.
Symptoms
The FortiGate remains outside the HA cluster. HA debug output can indicate an HA password mismatch.
Environment
FortiGate HA clusters; all FortiGate models and versions.
FortiOS version
All versions
Root Cause
The HA password differs between the primary and secondary FortiGate units.
Solution
- Enable HA communication and synchronization debugging to determine why the FortiGate is not joining the cluster:
diagnose debug application hatalk -1
diagnose debug application hasync -1
diagnose debug console timestamp enable
diagnose debug enable
-
Review the debug output for an HA password mismatch.
-
Disable debugging after collecting the required output:
diagnose debug disable
- Configure the correct HA password on the primary or secondary FortiGate. The password must be identical on both units:
config system ha
set password "ha_password"
end
- Allow the FortiGate to join the HA cluster after the matching password is configured.
Verification
Confirm that the FortiGate joins the HA cluster after both the primary and secondary firewalls use the same HA password.
Tags
No tags yet.
Community rating
— / 5 (0)
Discussion (0)
No comments yet.