Why Device HA show sync fail on active role after reboot, while passive role show sync successfully?

Options
Zyxel_James
Zyxel_James Posts: 839 image  Zyxel Employee
Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate 100 Answers

Question: Why Device HA show sync fail on active role after reboot, while passive role show sync successfully?

Answer:
This behavior is not a bug but an expected operational characteristic under specific reboot conditions for your Zyxel firewall HA Pro cluster.

Explanation of the Behavior
During a scheduled reboot, if the active firewall completes its boot process and assumes the active role before the passive unit has fully booted:

The active firewall initiates the HA process and attempts to synchronize with the passive unit. This includes sending synchronization data and performing a "sync status request."
The "sync status request" is a one-time check performed during this initial phase.
If the passive firewall is still in its booting phase, its sync port may not be ready or fully initialized to respond to this request.
As a result, the active firewall reports the sync status as "Fail" because it did not receive a timely response from the passive unit during the initial check.