ha synchronize
Use this command to manually control the synchronization of configuration files and FortiGuard service-related packages from the active HA appliance to the standby appliance.
Typically, most HA synchronization happens automatically, whenever changes are made. However, in some cases, you may want to use this command to manually initiate full or partial HA synchronization.
• To delay synchronization to a more convenient time if you are planning to make large batch changes, and therefore delayed synchronization is preferable for network performance reasons
• To manually force synchronization of files that are not automatically synchronized
• To trigger automatic synchronization if it has been interrupted due to HA link failure, daemon crashes, etc.
To use this command, your administrator account’s access control profile must have either
w or
rw permission to the
sysgrp area. For more information, see
“Permissions”.
Syntax
Variable | Description | Default |
synchronize {all | avupd | cli | geodb | sys} | Select which part of the configuration and/or FortiGuard service-related packages to synchronize. • all — Entire configuration, including CLI configuration, system files, and signature databases. • avupd — Only the FortiGuard Antivirus service package, including the virus signatures, scan engine, and proxy. • cli — Only the core CLI configuration file (fwb_system.conf). (You can use the show command to view the contents of the configuration file.) • sys — Only the IP Reputation Database (IRDB) and system files such as X.509 certificates. Note: This command has no effect if you use the command execute ha synchronize stop. to pause it manually. | No default. |
synchronize {start | stop} | Select whether to start or stop synchronization. | No default. |
Example
This example shows how to manually synchronize the virus signature and engine package to the standby appliance.
FortiWeb # execute ha synchronize avupd
starting synchronize with HA master...
Related topics