<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Issue on updating cert on Palo Alto FW pair in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/issue-on-updating-cert-on-palo-alto-fw-pair/m-p/284983#M76374</link>
    <description>&lt;P&gt;I got an issue to update a cert on PA pair.&lt;/P&gt;&lt;P&gt;The issue is very similar to what it describes under&lt;/P&gt;&lt;P&gt;&lt;A href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail%3Fid%3DkA10g000000CldECAS&amp;amp;data=02%7C01%7Csupport-anz%40arrow.com%7Cb86cf9c84b794b9df64908d727992a0f%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C637021411098632394&amp;amp;sdata=R%2BR9Ym0BrWpbtywbD2NvHLAgz1X1lS93sZGQPMwO08A%3D&amp;amp;reserved=0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CldECAS&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I import the new cert to both PA FW units and change config to use the new cert. However it comes with config out-of-sync issue and somehow the new cert on passive unit is removed after committing config.&lt;/P&gt;&lt;P&gt;any fix for the issue?&lt;/P&gt;</description>
    <pubDate>Mon, 26 Aug 2019 06:45:18 GMT</pubDate>
    <dc:creator>Jatin.Singh</dc:creator>
    <dc:date>2019-08-26T06:45:18Z</dc:date>
    <item>
      <title>Issue on updating cert on Palo Alto FW pair</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-on-updating-cert-on-palo-alto-fw-pair/m-p/284983#M76374</link>
      <description>&lt;P&gt;I got an issue to update a cert on PA pair.&lt;/P&gt;&lt;P&gt;The issue is very similar to what it describes under&lt;/P&gt;&lt;P&gt;&lt;A href="https://nam04.safelinks.protection.outlook.com/?url=https%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail%3Fid%3DkA10g000000CldECAS&amp;amp;data=02%7C01%7Csupport-anz%40arrow.com%7Cb86cf9c84b794b9df64908d727992a0f%7C0beb0c359cbb4feb99e5589e415c7944%7C1%7C0%7C637021411098632394&amp;amp;sdata=R%2BR9Ym0BrWpbtywbD2NvHLAgz1X1lS93sZGQPMwO08A%3D&amp;amp;reserved=0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CldECAS&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I import the new cert to both PA FW units and change config to use the new cert. However it comes with config out-of-sync issue and somehow the new cert on passive unit is removed after committing config.&lt;/P&gt;&lt;P&gt;any fix for the issue?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2019 06:45:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-on-updating-cert-on-palo-alto-fw-pair/m-p/284983#M76374</guid>
      <dc:creator>Jatin.Singh</dc:creator>
      <dc:date>2019-08-26T06:45:18Z</dc:date>
    </item>
    <item>
      <title>Re: Issue on updating cert on Palo Alto FW pair</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/issue-on-updating-cert-on-palo-alto-fw-pair/m-p/285132#M76387</link>
      <description>&lt;P&gt;This is what I would do (thinking out of the box)&lt;/P&gt;&lt;P&gt;If HA firewalls....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Export the configurtion from the active FW.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Import the configuration in the passive FW&lt;/P&gt;&lt;P&gt;Now, both FWs have 100% the exact config.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the passive FW, change the config to modify/update the config to use the original mgmt IP&lt;/P&gt;&lt;P&gt;On the passive FW, because it has the exact HA configuration as the active FW, modify it so that is has the orignal HA settings that the standby FW would have.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Commit on the standby&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, you have the cert on both FWs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Aug 2019 20:20:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/issue-on-updating-cert-on-palo-alto-fw-pair/m-p/285132#M76387</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2019-08-26T20:20:26Z</dc:date>
    </item>
  </channel>
</rss>

