← Back to knowledge base
high

Troubleshooting an HA status of 'Unknown' on FortiGate

Confirmed 9/18/2026

Problem

The FortiGate GUI reports the HA cluster status as 'Unknown'. This condition can result from mismatched firmware, split-brain, heartbeat-device configuration, or failed HA checksum communication between cluster members.

Symptoms

The GUI displays HA status as 'Unknown'. Additional indicators can include: `diagnose system ha checksum cluster` returning a checksum for only one member; `get system ha status` listing both members but showing the secondary checksum as `00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00`; an out-of-sync secondary; or HA debug messages showing a timeout to `169.254.0.1`, such as `<hasync:WARN> conn=0x10969010 abort: rt=-2, dst=169.254.0.1, sync_type=5(conf)` and `[__ha_send_req_ex:1482] pid-7688 ha req connect failed: type=43, dst_ip=169.254.0.1, error=110(Connection timed out)`.

Environment

FortiGate HA clusters, including HA active-passive deployments. The source examples use FortiGate-61F members and a FortiGate-1801F HA A-P cluster.

FortiOS version

The firmware-mismatch example uses FortiGate-61F v7.4.7,build2731,250120 (GA.M) on the primary and FortiGate-61F v7.4.5,build2702,240916 (GA.M) on the secondary. The general affected version is null.

Root Cause

Possible causes include different firmware versions on the HA members, an HA split-brain condition, use of `ha` and `mgmt` interfaces as `hbdev` ports, or failure of the secondary to provide a valid HA checksum. When the secondary checksum is empty or all zeros, HASYNC or HATALK communication may be stalled or timing out.

Solution

  1. Check the firmware version on both FortiGate cluster members:
get system status

Access the secondary through the CLI if necessary. In the documented mismatch example, the primary reports:

cgw-pri-XXXXX-gatech # get system status
Version: FortiGate-61F v7.4.7,build2731,250120 (GA.M)
First GA patch build date: 230509
Security Level: High
Firmware Signature: certified

The secondary reports:

cgw-sec-XXXX-gatech # get system status
Version: FortiGate-61F v7.4.5,build2702,240916 (GA.M)
First GA patch build date: 230509
Security Level: 2
Firmware Signature: certified

If the versions differ, align the firmware versions according to the intended HA firmware state.

  1. Determine whether the cluster is in split-brain. If present, follow the Fortinet procedure titled Technical Tip: High Availability - Split Brain.

  2. Check whether the ha and mgmt interfaces are configured as hbdev ports. If so, follow Technical Tip: HA out-of-sync and 'No route to host' error when accessing secondary device from CLI.

  3. If the cluster must be returned to its earlier firmware, follow Technical Tip: How to revert HA cluster unit to the previous firmware image.

  4. Compare the cluster checksum and HA membership:

diagnose system ha checksum cluster
get system ha status

The abbreviated form used in the source is also:

di sys ha checksum cluster

If the checksum command shows only one device while get system ha status lists both units, restart the HASYNC daemon on the primary:

fnsysctl killall hasync
  1. If diagnose system ha checksum cluster shows a checksum for only one unit and get system ha status reports the secondary checksum as all zeros, collect HA communication debug output while trying to connect from the primary to the secondary:
diagnose debug application hatalk -1
diagnose debug application hasync -1
diagnose debug enable

A timeout can appear as:

<hasync:WARN> conn=0x10969010 abort: rt=-2, dst=169.254.0.1, sync_type=5(conf)
[__ha_send_req_ex:1482] pid-7688 ha req connect failed: type=43, dst_ip=169.254.0.1, error=110(Connection timed out)
  1. During a maintenance window, restart the HATALK daemon on the primary, restart HA synchronization, and recalculate the checksum:
fnsysctl killall hatalk

execute ha synchronize stop
execute ha synchronize start
diagnose system ha checksum recalculate

Restarting hatalk can temporarily interrupt HA communication, so do not perform this action outside an approved maintenance window.

Verification

Run the following commands after remediation:

diagnose system ha checksum cluster
get system ha status

Confirm that both cluster members return valid checksums, the secondary checksum is no longer 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00, configuration status is in-sync, and the GUI no longer reports the HA state as 'Unknown'.

Rollback

If firmware changes must be reversed, use the Fortinet procedure titled Technical Tip: How to revert HA cluster unit to the previous firmware image. No separate rollback procedure is provided for restarting HASYNC or HATALK.

Tags

No tags yet.

Community rating

— / 5 (0)

Discussion (0)

    No comments yet.