<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to Login on Secondary Device in Active Passive HA Using Superuser in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/unable-to-login-on-secondary-device-in-active-passive-ha-using/m-p/1223439#M5670</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/747125303"&gt;@Mebinbaby&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That is a good one.&amp;nbsp; The only possibility that I can think of is that the master key was configured on the active NGFW, but not the passive.&amp;nbsp; The master key encrypts passwords and is not synced between HA pairs and must be configured locally.&amp;nbsp; &lt;A href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/high-availability/reference-ha-synchronization" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/high-availability/reference-ha-synchronization&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since your configuration is safely saved on the active NGFW, you can factory reset the passive.&amp;nbsp; Configure HA, and sync the configuration again.&amp;nbsp; You will still need to configure the master key on the passive if it was changed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
    <pubDate>Tue, 11 Mar 2025 12:36:53 GMT</pubDate>
    <dc:creator>TomYoung</dc:creator>
    <dc:date>2025-03-11T12:36:53Z</dc:date>
    <item>
      <title>Unable to Login on Secondary Device in Active Passive HA Using Superuser</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/unable-to-login-on-secondary-device-in-active-passive-ha-using/m-p/1223407#M5667</link>
      <description>&lt;P data-start="145" data-end="158"&gt;Hello Team,&lt;/P&gt;
&lt;P data-start="145" data-end="158"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="160" data-end="614"&gt;We are currently facing an issue with logging into the secondary firewall in an Active-Passive HA setup using any superuser credentials other than the admin credentials.&lt;/P&gt;
&lt;P data-start="160" data-end="614"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="160" data-end="614"&gt;When we create a new superuser account or make changes on the active firewall, they are successfully replicated on the passive firewall, indicating that HA synchronization is working properly. However, we are unable to log in to the secondary device using any superuser credentials.&lt;/P&gt;
&lt;P data-start="160" data-end="614"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="616" data-end="864"&gt;We are not using any authentication profile, and after checking the system logs, we found no entries related to credentials or authentication.&lt;/P&gt;
&lt;P data-start="616" data-end="864"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="616" data-end="864"&gt;Additionally, we have tried performing a hard reboot of the secondary firewall, but the issue persists.&lt;/P&gt;
&lt;P data-start="616" data-end="864"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="866" data-end="997"&gt;Has anyone encountered a similar issue? Kindly assist with possible resolutions or troubleshooting steps based on your expertise.&lt;/P&gt;
&lt;P data-start="866" data-end="997"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P data-start="999" data-end="1039"&gt;Thank you in advance for your support.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2025 04:56:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/unable-to-login-on-secondary-device-in-active-passive-ha-using/m-p/1223407#M5667</guid>
      <dc:creator>Mebinbaby</dc:creator>
      <dc:date>2025-03-11T04:56:16Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to Login on Secondary Device in Active Passive HA Using Superuser</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/unable-to-login-on-secondary-device-in-active-passive-ha-using/m-p/1223439#M5670</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/747125303"&gt;@Mebinbaby&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That is a good one.&amp;nbsp; The only possibility that I can think of is that the master key was configured on the active NGFW, but not the passive.&amp;nbsp; The master key encrypts passwords and is not synced between HA pairs and must be configured locally.&amp;nbsp; &lt;A href="https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/high-availability/reference-ha-synchronization" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/11-0/pan-os-admin/high-availability/reference-ha-synchronization&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since your configuration is safely saved on the active NGFW, you can factory reset the passive.&amp;nbsp; Configure HA, and sync the configuration again.&amp;nbsp; You will still need to configure the master key on the passive if it was changed.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Tue, 11 Mar 2025 12:36:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/unable-to-login-on-secondary-device-in-active-passive-ha-using/m-p/1223439#M5670</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2025-03-11T12:36:53Z</dc:date>
    </item>
  </channel>
</rss>

