<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: New local users created not working on FW Active but yes working on FW Passive in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/new-local-users-created-not-working-on-fw-active-but-yes-working/m-p/589989#M117564</link>
    <description>&lt;P&gt;Are you using the management interface to connect to the firewalls or data interfaces?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Because it seems to me that you may have an interface management profile with SSH allowed on the firewall where it works, but not on the other firewall. Interface management profile does not sync in an A/P HA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any useful information from the logs on the firewall where you can't access the GUI?&lt;/P&gt;</description>
    <pubDate>Thu, 20 Jun 2024 10:41:12 GMT</pubDate>
    <dc:creator>FadiSakkal11</dc:creator>
    <dc:date>2024-06-20T10:41:12Z</dc:date>
    <item>
      <title>New local users created not working on FW Active but yes working on FW Passive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-local-users-created-not-working-on-fw-active-but-yes-working/m-p/589819#M117534</link>
      <description>&lt;P&gt;Hello team&lt;/P&gt;
&lt;P&gt;Currently, I have a pair of FW 1410 &lt;SPAN&gt;Version:&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;11.0.4-h2&lt;/SPAN&gt;, passive active and I have encountered the following problem&lt;/P&gt;
&lt;P&gt;When creating new local users, with permissions, superuser I can not access via SSH to them locally but I can do it via GUI and all other users created previously.i.e. Users created some time ago in the FW are working correctly via GUI or CLI.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the Passive FW I have no such problem, I can access at the time of creating new local users via CLI or GUI. Also I tried to do a failover and the FW that now is Passive works fine also on Active mode.Then the problem is always located in the same FW, whether it is passive or active.&lt;/P&gt;
&lt;P&gt;I have already restarted the FW and loaded a new configuration file without success.&lt;/P&gt;
&lt;P&gt;Any ideas?&lt;/P&gt;
&lt;P&gt;The error CLI&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Alpalo_0-1718722651633.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60397iF5A4435315660264/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Alpalo_0-1718722651633.png" alt="Alpalo_0-1718722651633.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;System logs in FW Active looks like everything is fine.:-(&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Alpalo_1-1718722724774.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/60398i7E6B67D7789E075D/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Alpalo_1-1718722724774.png" alt="Alpalo_1-1718722724774.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2024 06:39:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-local-users-created-not-working-on-fw-active-but-yes-working/m-p/589819#M117534</guid>
      <dc:creator>Alpalo</dc:creator>
      <dc:date>2024-06-21T06:39:13Z</dc:date>
    </item>
    <item>
      <title>Re: New local users created not working on FW Active but yes working on FW Passive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-local-users-created-not-working-on-fw-active-but-yes-working/m-p/589969#M117561</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192671"&gt;@Alpalo&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could you try the following solutions:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HAsiCAG" target="_blank" rel="noopener"&gt;In a HA pair, secondary Firewall's ssh connectivity(management port ) is lost&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope this helps,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2024 08:21:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-local-users-created-not-working-on-fw-active-but-yes-working/m-p/589969#M117561</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2024-06-20T08:21:35Z</dc:date>
    </item>
    <item>
      <title>Re: New local users created not working on FW Active but yes working on FW Passive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-local-users-created-not-working-on-fw-active-but-yes-working/m-p/589987#M117562</link>
      <description>&lt;P&gt;Thanks for your answer, the strange thing is that with old created users the access works correctly, it does not work with locally created and newly created users. do you undesrtand me?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2024 10:23:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-local-users-created-not-working-on-fw-active-but-yes-working/m-p/589987#M117562</guid>
      <dc:creator>Alpalo</dc:creator>
      <dc:date>2024-06-20T10:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: New local users created not working on FW Active but yes working on FW Passive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-local-users-created-not-working-on-fw-active-but-yes-working/m-p/589989#M117564</link>
      <description>&lt;P&gt;Are you using the management interface to connect to the firewalls or data interfaces?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Because it seems to me that you may have an interface management profile with SSH allowed on the firewall where it works, but not on the other firewall. Interface management profile does not sync in an A/P HA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any useful information from the logs on the firewall where you can't access the GUI?&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jun 2024 10:41:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-local-users-created-not-working-on-fw-active-but-yes-working/m-p/589989#M117564</guid>
      <dc:creator>FadiSakkal11</dc:creator>
      <dc:date>2024-06-20T10:41:12Z</dc:date>
    </item>
    <item>
      <title>Re: New local users created not working on FW Active but yes working on FW Passive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-local-users-created-not-working-on-fw-active-but-yes-working/m-p/590063#M117573</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;No, it's not that, SSH is active in both and in the logs you can see that the user logs in correctly &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2024 06:37:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-local-users-created-not-working-on-fw-active-but-yes-working/m-p/590063#M117573</guid>
      <dc:creator>Alpalo</dc:creator>
      <dc:date>2024-06-21T06:37:00Z</dc:date>
    </item>
    <item>
      <title>Re: New local users created not working on FW Active but yes working on FW Passive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-local-users-created-not-working-on-fw-active-but-yes-working/m-p/590139#M117579</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192671"&gt;@Alpalo&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;When you're looking at the "active" firewall that isn't allowing SSH login (which I'm just going to term non-functional) and compare it to the "passive" firewall (which is hence forth functional) have you run a configuration audit between the two to validate that they're actually configured the same? That's where I would start, so you can validate that none of the non-sync'd information between the two isn't accounting for the issue as &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/698183931"&gt;@FadiSakkal11&lt;/a&gt; mentioned. Nothing should be causing the issue that you described, but sometimes people get so locked into the issue that they overlook something simple.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It honestly sounds like you're not actually creating Superuser accounts and the accounts created don't actually have a CLI role assigned. That would fit the error that you're seeing alongside the fact that you're seeing a successful auth log. When you say that you have already restarted the firewall, what exactly did you restart? Did you restart the entire box, or did you just restart the management-server?&lt;/P&gt;</description>
      <pubDate>Sun, 23 Jun 2024 02:50:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-local-users-created-not-working-on-fw-active-but-yes-working/m-p/590139#M117579</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2024-06-23T02:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: New local users created not working on FW Active but yes working on FW Passive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-local-users-created-not-working-on-fw-active-but-yes-working/m-p/590696#M117656</link>
      <description>&lt;P&gt;The configuration is identical.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2024 08:57:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-local-users-created-not-working-on-fw-active-but-yes-working/m-p/590696#M117656</guid>
      <dc:creator>Alpalo</dc:creator>
      <dc:date>2024-06-28T08:57:10Z</dc:date>
    </item>
    <item>
      <title>Re: New local users created not working on FW Active but yes working on FW Passive</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/new-local-users-created-not-working-on-fw-active-but-yes-working/m-p/595475#M118503</link>
      <description>&lt;P&gt;Im having the same issue with 11.1.2H3 code...&amp;nbsp; older admin pw working but newly created local users arent working.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 21 Aug 2024 13:19:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/new-local-users-created-not-working-on-fw-active-but-yes-working/m-p/595475#M118503</guid>
      <dc:creator>Nicole_Perez</dc:creator>
      <dc:date>2024-08-21T13:19:31Z</dc:date>
    </item>
  </channel>
</rss>

