- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-17-2022 11:04 AM
Ok so I may have made a mistake but I want to know the steps to recover and gain control back.
I changed the mastr key on Panorama and then proceeded to deploy same master key to 2 test firewalls. Both failed, one is a standalone VM, another to be removed disconnected HA pair, one of them in the pair is already turned off.
I then reverted config on panorama to earlier version hoping it might resolve. But didn't. It seems it doesn't have the key but the dates are still there.
It does let me push config to standalone VM with which the key date matches to Panorama but there is no custom key.
But on physical dates don't show so its still at default, doesn't let me push config template/device group.
I don't remember doing anything else for VM for its dates to be same as in Panorama, with no key set.
How can i restore control from Panorama, and move away from default keys.
08-19-2022 04:27 PM
My test firewall, soon to be out of commission had a bug. Had to update firmware on it.
Another inconsistency arose from panorama losing connectivity with some firewalls and still key is deployed successfully but panorama deploy window shows failure. Its resolved for all firewalls now.
08-19-2022 09:21 AM
https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/manage-the-master-key...
Sounds like you didn't follow the documented process to change the master key? If I'm not mistaken, and I 100% could be wrong as this is dated, the default master key value is 'p1a2l3o4a5l6t7o8'.
08-19-2022 04:27 PM
My test firewall, soon to be out of commission had a bug. Had to update firmware on it.
Another inconsistency arose from panorama losing connectivity with some firewalls and still key is deployed successfully but panorama deploy window shows failure. Its resolved for all firewalls now.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!