Master Key issue with Panaroma managed firewall?

cancel
Showing results for 
Search instead for 
Did you mean: 

Master Key issue with Panaroma managed firewall?

L4 Transporter

Ok so I may have made a mistake but I want to know the steps to recover and gain control back.

 

I changed the mastr key on Panorama and then proceeded to deploy same master key to 2 test firewalls. Both failed, one is a standalone VM, another to be removed disconnected HA pair, one of them in the pair is already turned off.

I then reverted config on panorama to earlier version hoping it might resolve. But didn't. It seems it doesn't have the key but the dates are still there.

 

It does let me push config to standalone VM with which the key date matches to Panorama but there is no custom key. 

But on physical dates don't show so its still at default, doesn't let me push config template/device group.

I don't remember doing anything else for VM for its dates to be same as in Panorama, with no key set.

 

How can i restore control from Panorama, and move away from default keys. 

 

1 ACCEPTED SOLUTION

Accepted Solutions

My test firewall, soon to be out of commission had a bug. Had to update firmware on it.

Another inconsistency arose from panorama losing connectivity with some firewalls and still key is deployed successfully but panorama deploy window shows failure. Its resolved for all firewalls now.

View solution in original post

2 REPLIES 2

Cyber Elite
Cyber Elite

https://docs.paloaltonetworks.com/panorama/9-1/panorama-admin/manage-firewalls/manage-the-master-key...

Sounds like you didn't follow the documented process to change the master key? If I'm not mistaken, and I 100% could be wrong as this is dated, the default master key value is 'p1a2l3o4a5l6t7o8'. 

My test firewall, soon to be out of commission had a bug. Had to update firmware on it.

Another inconsistency arose from panorama losing connectivity with some firewalls and still key is deployed successfully but panorama deploy window shows failure. Its resolved for all firewalls now.

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!