<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Commit failed and firewall now down after reboot in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/commit-failed-and-firewall-now-down-after-reboot/m-p/1260317#M7044</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a weird issue on a cluster of two firewalls on active/active mode.&lt;/P&gt;
&lt;P&gt;Yesterday I tried to commit a small change on our policy, it was OK on the primary but it de-sync the secondary so I tried to sync to peer manually with no luck.&lt;/P&gt;
&lt;P&gt;On the secondary I tried to commit localy and I had this error : &lt;BR /&gt;Unable to generate IKE VPN transform(Module: ikemgr)&lt;/P&gt;
&lt;P&gt;client ikemgr phase 1 failure&lt;/P&gt;
&lt;P&gt;Commit failed&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also tried to load an old conf and commit: same issue&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I still had the gui but in cli, the connection with local and ldaps accounts was KO (I had the prompt but the fw rejected the connection). On the dashboard the HA was healthy, there were only the sync issue.&lt;/P&gt;
&lt;P&gt;I rebooted the firewall and now I lost the gui access.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the primary it seems that only the HA3 is up, HA1 and HA2 are down, peer is unknown.&lt;/P&gt;
&lt;P&gt;And today I'm not able to commit on the primary with the same kind of issue as the secondary:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unable to generate IKE VPN transform(Module: ikemgr)&lt;/P&gt;
&lt;P&gt;client ikemgr phase 1 failure&lt;/P&gt;
&lt;P&gt;Commit failed&lt;/P&gt;
&lt;P&gt;Also, we cannot log on ssh like the secondary before the reboot.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I didn't use the ipsec module, there is no specific ike gateways, ipsec crypto or ike crypto profile. We do not use this cluster for ipsec connectivity.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your help guys&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Ben&lt;/P&gt;</description>
    <pubDate>Wed, 29 Jul 2026 12:13:20 GMT</pubDate>
    <dc:creator>benjamin.kowalczyk</dc:creator>
    <dc:date>2026-07-29T12:13:20Z</dc:date>
    <item>
      <title>Commit failed and firewall now down after reboot</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/commit-failed-and-firewall-now-down-after-reboot/m-p/1260317#M7044</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have a weird issue on a cluster of two firewalls on active/active mode.&lt;/P&gt;
&lt;P&gt;Yesterday I tried to commit a small change on our policy, it was OK on the primary but it de-sync the secondary so I tried to sync to peer manually with no luck.&lt;/P&gt;
&lt;P&gt;On the secondary I tried to commit localy and I had this error : &lt;BR /&gt;Unable to generate IKE VPN transform(Module: ikemgr)&lt;/P&gt;
&lt;P&gt;client ikemgr phase 1 failure&lt;/P&gt;
&lt;P&gt;Commit failed&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I also tried to load an old conf and commit: same issue&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I still had the gui but in cli, the connection with local and ldaps accounts was KO (I had the prompt but the fw rejected the connection). On the dashboard the HA was healthy, there were only the sync issue.&lt;/P&gt;
&lt;P&gt;I rebooted the firewall and now I lost the gui access.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the primary it seems that only the HA3 is up, HA1 and HA2 are down, peer is unknown.&lt;/P&gt;
&lt;P&gt;And today I'm not able to commit on the primary with the same kind of issue as the secondary:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Unable to generate IKE VPN transform(Module: ikemgr)&lt;/P&gt;
&lt;P&gt;client ikemgr phase 1 failure&lt;/P&gt;
&lt;P&gt;Commit failed&lt;/P&gt;
&lt;P&gt;Also, we cannot log on ssh like the secondary before the reboot.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I didn't use the ipsec module, there is no specific ike gateways, ipsec crypto or ike crypto profile. We do not use this cluster for ipsec connectivity.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for your help guys&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Ben&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2026 12:13:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/commit-failed-and-firewall-now-down-after-reboot/m-p/1260317#M7044</guid>
      <dc:creator>benjamin.kowalczyk</dc:creator>
      <dc:date>2026-07-29T12:13:20Z</dc:date>
    </item>
    <item>
      <title>Re: Commit failed and firewall now down after reboot</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/commit-failed-and-firewall-now-down-after-reboot/m-p/1260319#M7045</link>
      <description>&lt;P&gt;I forgot something, even a techsupport failed..&lt;/P&gt;
&lt;P&gt;I will try tomorrow morning to have console access and try to execute some commands to understand what's happening&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2026 12:18:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/commit-failed-and-firewall-now-down-after-reboot/m-p/1260319#M7045</guid>
      <dc:creator>benjamin.kowalczyk</dc:creator>
      <dc:date>2026-07-29T12:18:22Z</dc:date>
    </item>
    <item>
      <title>Re: Commit failed and firewall now down after reboot</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/commit-failed-and-firewall-now-down-after-reboot/m-p/1260323#M7046</link>
      <description>&lt;P&gt;sounds like you may have changed the master key? did you set it identical on both peers ?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jul 2026 14:55:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/commit-failed-and-firewall-now-down-after-reboot/m-p/1260323#M7046</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2026-07-29T14:55:52Z</dc:date>
    </item>
  </channel>
</rss>

