A/P High Availability not syncing - ssl vpn cert file - processing failed

Printer Friendly Page

Symptom

HA-Sync job on HA peer fails, details on the job id reveal an error similar to the one below:

 

Inside of the CLI:

admin@firewall(passive)> show jobs id <job id>

 

Enqueued ID Type Status Result Completed

--------------------------------------------------------------------------

2015/06/06 19:09:47 9 HA-Sync FIN FAIL 19:09:52

 

Warnings:

Details:ssl vpn cert file (GlobalProtect) processing failed

(Module: rasmgr)

global-protect-gateway tunnel interface (tunnel.1) in vsys (vsys1) parsing failed

(Module: rasmgr)

Commit failed

 

Cause

In this example, the GlobalProtect certificate is selected to also be the WebGUI certificate.

 

To verify this, go inside of the WebGUI, Device > Certificate Management > Certificates and click on the certificate name (GlobalProtect in this example), and you will see that "Certificate for Secure Web GUI" is selected.

Screen Shot 2015-01-28 at 11.30.02 AM.png

 

Solution

To resolve this error, remove the check for "Certificate for Secure Web GUI" from the GlobalProtect Certificate, then Commit the changes.

The HA will now Sync properly.

 

Screen Shot 2015-01-28 at 11.30.12 AM.png

 

If you need to use a SSL certificate for the WebGUI(Secure Web GUI), you will need to create and use a separate certificate for the WebGUI.

 

owner: mivaldi

 

Comments

I was able to fix this issue, here are the steps:

 

Export the config from the active device

Import the config into the passive device

Change the IPs of the management & HA interfaces so they are back to what they used to be

Commit

 

Now your devices will be in sync and using the same certificate for both Global Protect & the web GUI. Any further changes won't cause the issue anymore.

 

Ben