<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot Access Primary in HA Pair – Need Failover &amp;amp; Recovery Advice&amp;quot; in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-access-primary-in-ha-pair-need-failover-amp-recovery/m-p/1242309#M6471</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;The only way to recover a lost password is to factory restore the firewall which essentially wipes the configuration, unless you have Panorama and it still connects? To answer your questions:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1. Is our planned approach the best practice for recovering from lost access on the primary firewall in an HA setup?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I would take a similar action.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;2. Are there any additional precautions or commands we should consider during manual failover and reboot?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Precautions, since the config has not synced in a long time, there could be traffic that is blocked.&lt;/P&gt;
&lt;P&gt;CAUTION on resetting since the everything will be lost:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/ngfw/administration/firewall-administration/reset-the-firewall-to-factory-default-settings" target="_blank"&gt;https://docs.paloaltonetworks.com/ngfw/administration/firewall-administration/reset-the-firewall-to-factory-default-settings&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;3. Given the config drift, how can we best ensure synchronization without impacting live traffic?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;It can only be performed from the active unit unfortunately.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;4. Any known issues with very long uptime on Palo Alto firewalls causing credential/access problems?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I do not know of any however you can go through the release notes.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;5. Are there alternative methods to regain access to the primary firewall that we might have missed, IS there any logs we can fetch to confirm where is the issue?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you are getting logs from the active unit, it should show failed logins to the management interface. No other methods exist if you dont have the password.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Best of luck!&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 20 Nov 2025 16:44:06 GMT</pubDate>
    <dc:creator>OtakarKlier</dc:creator>
    <dc:date>2025-11-20T16:44:06Z</dc:date>
    <item>
      <title>Cannot Access Primary in HA Pair – Need Failover &amp; Recovery Advice"</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-access-primary-in-ha-pair-need-failover-amp-recovery/m-p/1242050#M6464</link>
      <description>&lt;P&gt;**Subject: Unable to Access Primary Firewall in HA Setup — Need Guidance on Failover and Recovery**&lt;/P&gt;&lt;P&gt;Hello Palo Alto Community,&lt;/P&gt;&lt;P&gt;We are currently facing an urgent issue with our Active/Passive Palo Alto firewall setup:&lt;/P&gt;&lt;P&gt;Palo Alto Model:PA-3220&lt;BR /&gt;VERSION:10.2.5&lt;BR /&gt;UPTIME:765 DAYS&lt;/P&gt;&lt;P&gt;- The primary firewall (IP .165) is active but we have lost admin login access due to credential issues.&lt;BR /&gt;- The firewall has been continuously running for approximately 2 years (over 700 days uptime).&lt;BR /&gt;- The secondary firewall (IP .166) is passive and fully accessible; HA sync is functional, but configuration sync has been out of date for about a year and config sync show red colour.&lt;BR /&gt;- When logging in via VIP, the session used to land on the secondary firewall previously which we were able to access, but now the primary is active for some reson and inaccessible now ,secondary is stil fine we can login to secondary without any issues but the primary same creds does not work which was working previously.&lt;BR /&gt;- Console access is also tried with no luck&lt;/P&gt;&lt;P&gt;**What we have planned:**&lt;BR /&gt;- We intend to manually trigger a failover to the secondary firewall by unplugging one of the links from the primary firewall to switch traffic.&lt;BR /&gt;- Once traffic is on the secondary, we plan to reboot the primary firewall to try and recover access, assuming the long uptime could be causing the issue.&lt;BR /&gt;- After reboot, we plan to manually sync configurations from the currently active secondary back to the primary to reconcile any differences.&lt;/P&gt;&lt;P&gt;**Challenges:**&lt;BR /&gt;- We have no direct support contract with Palo Alto for this firewall, so we are relying on community expertise to navigate this safely and efficiently.&lt;BR /&gt;- We want to avoid traffic downtime and misconfiguration risks during failover and sync.&lt;/P&gt;&lt;P&gt;**Questions:**&lt;BR /&gt;1. Is our planned approach the best practice for recovering from lost access on the primary firewall in an HA setup?&lt;BR /&gt;2. Are there any additional precautions or commands we should consider during manual failover and reboot?&lt;BR /&gt;3. Given the config drift, how can we best ensure synchronization without impacting live traffic?&lt;BR /&gt;4. Any known issues with very long uptime on Palo Alto firewalls causing credential/access problems?&lt;BR /&gt;5. Are there alternative methods to regain access to the primary firewall that we might have missed, IS there any logs we can fetch to confirm where is the issue?&lt;/P&gt;&lt;P&gt;We appreciate any guidance, past experiences, or documentation references the community can provide. This situation is time-sensitive as the primary firewall is critical to our network security.&lt;/P&gt;&lt;P&gt;Thank you in advance for your support!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Nov 2025 03:12:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-access-primary-in-ha-pair-need-failover-amp-recovery/m-p/1242050#M6464</guid>
      <dc:creator>Aftab_786</dc:creator>
      <dc:date>2025-11-18T03:12:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Access Primary in HA Pair – Need Failover &amp; Recovery Advice"</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-access-primary-in-ha-pair-need-failover-amp-recovery/m-p/1242309#M6471</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;The only way to recover a lost password is to factory restore the firewall which essentially wipes the configuration, unless you have Panorama and it still connects? To answer your questions:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;1. Is our planned approach the best practice for recovering from lost access on the primary firewall in an HA setup?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I would take a similar action.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;2. Are there any additional precautions or commands we should consider during manual failover and reboot?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Precautions, since the config has not synced in a long time, there could be traffic that is blocked.&lt;/P&gt;
&lt;P&gt;CAUTION on resetting since the everything will be lost:&amp;nbsp;&lt;A href="https://docs.paloaltonetworks.com/ngfw/administration/firewall-administration/reset-the-firewall-to-factory-default-settings" target="_blank"&gt;https://docs.paloaltonetworks.com/ngfw/administration/firewall-administration/reset-the-firewall-to-factory-default-settings&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;3. Given the config drift, how can we best ensure synchronization without impacting live traffic?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;It can only be performed from the active unit unfortunately.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;4. Any known issues with very long uptime on Palo Alto firewalls causing credential/access problems?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;I do not know of any however you can go through the release notes.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;5. Are there alternative methods to regain access to the primary firewall that we might have missed, IS there any logs we can fetch to confirm where is the issue?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;If you are getting logs from the active unit, it should show failed logins to the management interface. No other methods exist if you dont have the password.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Best of luck!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Nov 2025 16:44:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-access-primary-in-ha-pair-need-failover-amp-recovery/m-p/1242309#M6471</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2025-11-20T16:44:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot Access Primary in HA Pair – Need Failover &amp; Recovery Advice"</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-access-primary-in-ha-pair-need-failover-amp-recovery/m-p/1242344#M6473</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Precautions, since the config has not synced in a long time, there could be traffic that is blocked.----traffic is not a prob here because we do not have much configs in this device also we are not oftenly making much changes on this firewall , our main goal is traffic should work , sync should work and we should regain access to the primary firewall after a reboot as we know username and password that we are using is correct&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Nov 2025 03:01:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/cannot-access-primary-in-ha-pair-need-failover-amp-recovery/m-p/1242344#M6473</guid>
      <dc:creator>Aftab_786</dc:creator>
      <dc:date>2025-11-21T03:01:01Z</dc:date>
    </item>
  </channel>
</rss>

