can't sign in paloalto pa-440 device with admin account

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

can't sign in paloalto pa-440 device with admin account

L1 Bithead

invalid username or password to login PaloAlto firewall PA-440

1 accepted solution

Accepted Solutions

Hi Mshekh,

I was working with Palo Alto engineer to go to maintenance mode and boot from "Debut reboot" on passive device first. And I am able to login my admin account. Create "Save named configuration snapshot" and export "Save named configuration snapshot" file for backup. Then failover from primary to this secondary. Repeat on the primary device to boot from "Debut reboot", and able to login admin account. create save configuration file. Finally, failover back to primary device. It seems my two devices just need to reboot, then I am able to login again.

View solution in original post

9 REPLIES 9

L4 Transporter

Hi @A.Yang595201 ,

 

Can you share more details, is it a new device or it was working and suddenly you are not able to login to device.

Additionally, Please refer the below kb to recover the password.

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClkxCAC



Best Regards,
Mohammad Talib

It is a device has been setup in 2024. It is working few months since June, 2024. I tried to login both devices 1/14 with admin account. It said invalid username or password. Our devices, we did create password expire profile for users, but not for admin. Not sure why I can't login admin account. We do have HA device configured, and both devices I couldn't login with admin account. Two weeks ago, we do have UPS power failure issue on primary device, then it failover to secondary device. After primary device is power on. It failover back to primary. I notice I haven't login these both devices at least one month. I am not sure if I power off secondary device, then power back on, will help me to login secondary device? Any suggestions, Thanks

L4 Transporter

Hi @A.Yang595201 ,

 

May I check if the device is connected to Panorama or you are managing it locally.

Also are you able to login with other non-admin accounts.

 



Best Regards,
Mohammad Talib

We manage device locally. I couldn't login other non-admin accounts that I assigned to other IT staffs. If I restart the device one at a time, will it help, since we have HA configured?

L4 Transporter

Hi @A.Yang595201 ,

 

What is the running PAN-OS version at the device, you may try with restart the device but very less chances for recovery.

 

You have to follow the password recovery article to recover the password.

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClkxCAC

 



Best Regards,
Mohammad Talib

10.2.7-h3

L4 Transporter

Hi @A.Yang595201 ,

 

Thanks for info, Please try with recovery as per shared KB.

 

https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClkxCAC



Best Regards,
Mohammad Talib

Thanks for the KB link. I am able to create ticket with Palo Alto now. I will see what other options can solve this issue. I will post later if I have resolved. Thanks for your help

Hi Mshekh,

I was working with Palo Alto engineer to go to maintenance mode and boot from "Debut reboot" on passive device first. And I am able to login my admin account. Create "Save named configuration snapshot" and export "Save named configuration snapshot" file for backup. Then failover from primary to this secondary. Repeat on the primary device to boot from "Debut reboot", and able to login admin account. create save configuration file. Finally, failover back to primary device. It seems my two devices just need to reboot, then I am able to login again.

  • 1 accepted solution
  • 868 Views
  • 9 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!