<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Unable to SSH to Passive firewall, GUI OK in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-ssh-to-passive-firewall-gui-ok/m-p/448631#M100838</link>
    <description>&lt;P&gt;hello everyone,&lt;/P&gt;&lt;P&gt;I lost SSH access to my PA-3020 passive firewall on mgmt. interface.. I can access it via GUI.&lt;/P&gt;&lt;P&gt;for Active Firewall, both SSH and GUI are OK.&lt;/P&gt;&lt;P&gt;I think it happened after I did fixing weak ciphers and keys on mgmt. interface. interface for SSH access.&lt;/P&gt;&lt;P&gt;I did the following procedure&amp;nbsp; on both active/passive FW.&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PN5bCAG" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PN5bCAG&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;and I found the Palo recommended solution below, but I could not able to access the device console currently.&lt;/FONT&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Solution:&amp;nbsp;&lt;/STRONG&gt;&lt;OL&gt;&lt;LI&gt;On secondary FW, turn off SSH from the WebUI.&lt;/LI&gt;&lt;LI&gt;Log in through the console, first delete the existing configuration and then make the cipher changes again.&lt;/LI&gt;&lt;LI&gt;Restart the service&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"set ssh service-restart mgmt"&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;Then turned on SSH from the WebUI Or&amp;nbsp;You can change the SSH related configuration on both FW simultaneously and restart SSH service on management together.&amp;nbsp;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;FONT&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HAsiCAG" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HAsiCAG&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;is there any way to fix the issue by remote?&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;- can we fix by enabling telnet and access the device?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;- can we fix by rebooting passive device?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;- can we fix by running the following commands?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;&lt;SPAN&gt;&amp;gt; request high-availability sync-to-remote running-config (on Active)&lt;/SPAN&gt;&lt;BR /&gt;&lt;FONT&gt;&amp;gt; set ssh service-restart mgmt (on Passive)&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Please suggest. Thank you.&lt;/DIV&gt;</description>
    <pubDate>Fri, 19 Nov 2021 09:33:25 GMT</pubDate>
    <dc:creator>zinkt101</dc:creator>
    <dc:date>2021-11-19T09:33:25Z</dc:date>
    <item>
      <title>Unable to SSH to Passive firewall, GUI OK</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-ssh-to-passive-firewall-gui-ok/m-p/448631#M100838</link>
      <description>&lt;P&gt;hello everyone,&lt;/P&gt;&lt;P&gt;I lost SSH access to my PA-3020 passive firewall on mgmt. interface.. I can access it via GUI.&lt;/P&gt;&lt;P&gt;for Active Firewall, both SSH and GUI are OK.&lt;/P&gt;&lt;P&gt;I think it happened after I did fixing weak ciphers and keys on mgmt. interface. interface for SSH access.&lt;/P&gt;&lt;P&gt;I did the following procedure&amp;nbsp; on both active/passive FW.&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PN5bCAG" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PN5bCAG&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;and I found the Palo recommended solution below, but I could not able to access the device console currently.&lt;/FONT&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;STRONG&gt;Solution:&amp;nbsp;&lt;/STRONG&gt;&lt;OL&gt;&lt;LI&gt;On secondary FW, turn off SSH from the WebUI.&lt;/LI&gt;&lt;LI&gt;Log in through the console, first delete the existing configuration and then make the cipher changes again.&lt;/LI&gt;&lt;LI&gt;Restart the service&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;"set ssh service-restart mgmt"&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;Then turned on SSH from the WebUI Or&amp;nbsp;You can change the SSH related configuration on both FW simultaneously and restart SSH service on management together.&amp;nbsp;&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;FONT&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HAsiCAG" target="_blank" rel="noopener"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HAsiCAG&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;is there any way to fix the issue by remote?&amp;nbsp;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;- can we fix by enabling telnet and access the device?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;- can we fix by rebooting passive device?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;- can we fix by running the following commands?&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT&gt;&lt;SPAN&gt;&amp;gt; request high-availability sync-to-remote running-config (on Active)&lt;/SPAN&gt;&lt;BR /&gt;&lt;FONT&gt;&amp;gt; set ssh service-restart mgmt (on Passive)&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Please suggest. Thank you.&lt;/DIV&gt;</description>
      <pubDate>Fri, 19 Nov 2021 09:33:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-ssh-to-passive-firewall-gui-ok/m-p/448631#M100838</guid>
      <dc:creator>zinkt101</dc:creator>
      <dc:date>2021-11-19T09:33:25Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to SSH to Passive firewall, GUI OK</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-ssh-to-passive-firewall-gui-ok/m-p/448847#M100859</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/193973"&gt;@zinkt101&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;The&amp;nbsp;&lt;STRONG&gt;Important&amp;nbsp;&lt;/STRONG&gt;section of the KB you was following does kind of a bad job of calling it out, but you actually do need to ensure that you have active SSH sessions open to both devices while doing this procedure or you risk running into this sort of situation. It should also include, at least in my opinion, a warning that you should have easy access to the console interface on the device should something go wrong explicitly spelt out.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As for your current situation, part of the KB is running the config sync and restarting the ssh service on the passive node. If you for some reason lost access to the passive firewall during this process or didn't follow those two steps you end up in a situation like you have now. The fix for this is just finishing those steps and restart the ssh service through the console port.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since you don't have easy access to the passive device outside of the GUI, you can still sync the config from the active firewall and wait a bit for that to complete (monitor from the 'Tasks' tab on the GUI on the passive) and simply issue the ssh service-restart mgmt command through the api. Remember that&amp;nbsp;&lt;EM&gt;almost&amp;nbsp;&lt;/EM&gt;anything you can do on the CLI you can do through the XML API.&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;/api/?type=op&amp;amp;cmd=&amp;lt;set&amp;gt;&amp;lt;ssh&amp;gt;&amp;lt;service-restart&amp;gt;&amp;lt;mgmt&amp;gt;&amp;lt;/mgmt&amp;gt;&amp;lt;/service-restart&amp;gt;&amp;lt;/ssh&amp;gt;&amp;lt;/set&amp;gt;&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 20 Nov 2021 16:53:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-ssh-to-passive-firewall-gui-ok/m-p/448847#M100859</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2021-11-20T16:53:55Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to SSH to Passive firewall, GUI OK</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/unable-to-ssh-to-passive-firewall-gui-ok/m-p/449215#M100906</link>
      <description>&lt;P&gt;thank you for your reply and I will try to restart through the api.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Nov 2021 10:16:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/unable-to-ssh-to-passive-firewall-gui-ok/m-p/449215#M100906</guid>
      <dc:creator>zinkt101</dc:creator>
      <dc:date>2021-11-24T10:16:32Z</dc:date>
    </item>
  </channel>
</rss>

