Log into both firewalls
In the Dashboard > High Availability widget, you may notice the primary has change from active to passive.
On both firewalls go to
- Monitor > System
- Filter the log
- subtype eq ha
You should see a reason for the failover.
Often the link monitors fail (internet connection issue). You can check them here
- Device > High Availability > Link and Path Monitoring
- Link group will show the interfaces that need to be up (Layer 2)
- Path group will show the IP's the firewall will try to ping to confirm link is up (Layer 3)
Have seen the auto updates trigger failovers as well