<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Certificates duplicated from Primary to Secondary firewall in Palo alto in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/certificates-duplicated-from-primary-to-secondary-firewall-in/m-p/522689#M628</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have 2 Palo alto firewalls in HA mode (Active-standby).&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Palo alto mode: PA-3220&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;OS Version: 10.1.6-h3&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We create Unique certificates (for management, interdevice) in each firewall with hostname. After some time, the certificates in secondary firewall gets removed and the certificates from primary firewall are copied into secondary firewall..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="lia-message-author-rank lia-component-author-rank lia-component-message-view-widget-author-rank"&gt;Cyber Elite&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example: Primary firewall hostname and certificates: Hostname:PrimaryFW Certificate name: PrimaryFW&lt;/P&gt;
&lt;P&gt;Secondary firewall hostname: SecondaryFW; Certificate name: SecondaryFW&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After some time,, the seconday firewall certificates are deleted, and the primary firewall certificates are visible in the secondary firewall.. is it a bug?&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124013"&gt;@Jafar_Hussain&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/42079"&gt;@DelvinC&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Nov 2022 04:09:12 GMT</pubDate>
    <dc:creator>Sai14091990</dc:creator>
    <dc:date>2022-11-29T04:09:12Z</dc:date>
    <item>
      <title>Certificates duplicated from Primary to Secondary firewall in Palo alto</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/certificates-duplicated-from-primary-to-secondary-firewall-in/m-p/522689#M628</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have 2 Palo alto firewalls in HA mode (Active-standby).&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Palo alto mode: PA-3220&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;OS Version: 10.1.6-h3&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We create Unique certificates (for management, interdevice) in each firewall with hostname. After some time, the certificates in secondary firewall gets removed and the certificates from primary firewall are copied into secondary firewall..&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="lia-message-author-rank lia-component-author-rank lia-component-message-view-widget-author-rank"&gt;Cyber Elite&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example: Primary firewall hostname and certificates: Hostname:PrimaryFW Certificate name: PrimaryFW&lt;/P&gt;
&lt;P&gt;Secondary firewall hostname: SecondaryFW; Certificate name: SecondaryFW&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After some time,, the seconday firewall certificates are deleted, and the primary firewall certificates are visible in the secondary firewall.. is it a bug?&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/70130"&gt;@aleksandar.astardzhiev&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/124013"&gt;@Jafar_Hussain&lt;/a&gt;&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/42079"&gt;@DelvinC&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 04:09:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/certificates-duplicated-from-primary-to-secondary-firewall-in/m-p/522689#M628</guid>
      <dc:creator>Sai14091990</dc:creator>
      <dc:date>2022-11-29T04:09:12Z</dc:date>
    </item>
    <item>
      <title>Re: Certificates duplicated from Primary to Secondary firewall in Palo alto</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/certificates-duplicated-from-primary-to-secondary-firewall-in/m-p/522705#M630</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/259705"&gt;@Sai14091990&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;According to documentations certificates are not synced between Active/Passive HA member - &lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/high-availability/reference-ha-synchronization/what-settings-dont-sync-in-activepassive-ha" target="_blank"&gt;What Settings Don’t Sync in Active/Passive HA? (paloaltonetworks.com)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There is very important note mentioned on that link&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Astardzhiev_0-1669705997954.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/45744i8A74FAC62419B121/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Astardzhiev_0-1669705997954.png" alt="Astardzhiev_0-1669705997954.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So what you experience shouldn't be normal, and I suspect that you are using different certificate names. Don't confuse Common Name (CN) with name - latter is the name of the certificate object you put when importing/generating the certificate.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Try to import the certificate for secondary member again and set exactly the same name as the mgmt certificate on the primary member and see if this will help.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Nov 2022 07:17:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/certificates-duplicated-from-primary-to-secondary-firewall-in/m-p/522705#M630</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2022-11-29T07:17:14Z</dc:date>
    </item>
  </channel>
</rss>

