Troubleshooting an HA status of 'Unknown' on FortiGate
Confirmed 9/18/2026
Problem
The FortiGate GUI reports the HA cluster status as 'Unknown'. This condition can result from mismatched firmware, split-brain, heartbeat-device configuration, or failed HA checksum communication between cluster members.
Symptoms
The GUI displays HA status as 'Unknown'. Additional indicators can include: `diagnose system ha checksum cluster` returning a checksum for only one member; `get system ha status` listing both members but showing the secondary checksum as `00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00`; an out-of-sync secondary; or HA debug messages showing a timeout to `169.254.0.1`, such as `<hasync:WARN> conn=0x10969010 abort: rt=-2, dst=169.254.0.1, sync_type=5(conf)` and `[__ha_send_req_ex:1482] pid-7688 ha req connect failed: type=43, dst_ip=169.254.0.1, error=110(Connection timed out)`.
Environment
FortiGate HA clusters, including HA active-passive deployments. The source examples use FortiGate-61F members and a FortiGate-1801F HA A-P cluster.
FortiOS version
The firmware-mismatch example uses FortiGate-61F v7.4.7,build2731,250120 (GA.M) on the primary and FortiGate-61F v7.4.5,build2702,240916 (GA.M) on the secondary. The general affected version is null.
Root Cause
Possible causes include different firmware versions on the HA members, an HA split-brain condition, use of `ha` and `mgmt` interfaces as `hbdev` ports, or failure of the secondary to provide a valid HA checksum. When the secondary checksum is empty or all zeros, HASYNC or HATALK communication may be stalled or timing out.
Solution
- Check the firmware version on both FortiGate cluster members:
get system status
Access the secondary through the CLI if necessary. In the documented mismatch example, the primary reports:
cgw-pri-XXXXX-gatech # get system status
Version: FortiGate-61F v7.4.7,build2731,250120 (GA.M)
First GA patch build date: 230509
Security Level: High
Firmware Signature: certified
The secondary reports:
cgw-sec-XXXX-gatech # get system status
Version: FortiGate-61F v7.4.5,build2702,240916 (GA.M)
First GA patch build date: 230509
Security Level: 2
Firmware Signature: certified
If the versions differ, align the firmware versions according to the intended HA firmware state.
-
Determine whether the cluster is in split-brain. If present, follow the Fortinet procedure titled Technical Tip: High Availability - Split Brain.
-
Check whether the
haandmgmtinterfaces are configured ashbdevports. If so, follow Technical Tip: HA out-of-sync and 'No route to host' error when accessing secondary device from CLI. -
If the cluster must be returned to its earlier firmware, follow Technical Tip: How to revert HA cluster unit to the previous firmware image.
-
Compare the cluster checksum and HA membership:
diagnose system ha checksum cluster
get system ha status
The abbreviated form used in the source is also:
di sys ha checksum cluster
If the checksum command shows only one device while get system ha status lists both units, restart the HASYNC daemon on the primary:
fnsysctl killall hasync
- If
diagnose system ha checksum clustershows a checksum for only one unit andget system ha statusreports the secondary checksum as all zeros, collect HA communication debug output while trying to connect from the primary to the secondary:
diagnose debug application hatalk -1
diagnose debug application hasync -1
diagnose debug enable
A timeout can appear as:
<hasync:WARN> conn=0x10969010 abort: rt=-2, dst=169.254.0.1, sync_type=5(conf)
[__ha_send_req_ex:1482] pid-7688 ha req connect failed: type=43, dst_ip=169.254.0.1, error=110(Connection timed out)
- During a maintenance window, restart the HATALK daemon on the primary, restart HA synchronization, and recalculate the checksum:
fnsysctl killall hatalk
execute ha synchronize stop
execute ha synchronize start
diagnose system ha checksum recalculate
Restarting hatalk can temporarily interrupt HA communication, so do not perform this action outside an approved maintenance window.
Verification
Run the following commands after remediation:
diagnose system ha checksum cluster
get system ha status
Confirm that both cluster members return valid checksums, the secondary checksum is no longer 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00, configuration status is in-sync, and the GUI no longer reports the HA state as 'Unknown'.
Rollback
If firmware changes must be reversed, use the Fortinet procedure titled Technical Tip: How to revert HA cluster unit to the previous firmware image. No separate rollback procedure is provided for restarting HASYNC or HATALK.
Tags
No tags yet.
Community rating
— / 5 (0)
Discussion (0)
No comments yet.