- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-17-2025 07:11 PM - edited 11-17-2025 07:12 PM
**Subject: Unable to Access Primary Firewall in HA Setup — Need Guidance on Failover and Recovery**
Hello Palo Alto Community,
We are currently facing an urgent issue with our Active/Passive Palo Alto firewall setup:
Palo Alto Model:PA-3220
VERSION:10.2.5
UPTIME:765 DAYS
- The primary firewall (IP .165) is active but we have lost admin login access due to credential issues.
- The firewall has been continuously running for approximately 2 years (over 700 days uptime).
- The secondary firewall (IP .166) is passive and fully accessible; HA sync is functional, but configuration sync has been out of date for about a year and config sync show red colour.
- When logging in via VIP, the session used to land on the secondary firewall previously which we were able to access, but now the primary is active for some reson and inaccessible now ,secondary is stil fine we can login to secondary without any issues but the primary same creds does not work which was working previously.
- Console access is also tried with no luck
**What we have planned:**
- We intend to manually trigger a failover to the secondary firewall by unplugging one of the links from the primary firewall to switch traffic.
- Once traffic is on the secondary, we plan to reboot the primary firewall to try and recover access, assuming the long uptime could be causing the issue.
- After reboot, we plan to manually sync configurations from the currently active secondary back to the primary to reconcile any differences.
**Challenges:**
- We have no direct support contract with Palo Alto for this firewall, so we are relying on community expertise to navigate this safely and efficiently.
- We want to avoid traffic downtime and misconfiguration risks during failover and sync.
**Questions:**
1. Is our planned approach the best practice for recovering from lost access on the primary firewall in an HA setup?
2. Are there any additional precautions or commands we should consider during manual failover and reboot?
3. Given the config drift, how can we best ensure synchronization without impacting live traffic?
4. Any known issues with very long uptime on Palo Alto firewalls causing credential/access problems?
5. Are there alternative methods to regain access to the primary firewall that we might have missed, IS there any logs we can fetch to confirm where is the issue?
We appreciate any guidance, past experiences, or documentation references the community can provide. This situation is time-sensitive as the primary firewall is critical to our network security.
Thank you in advance for your support!
11-20-2025 08:44 AM
Hello,
The only way to recover a lost password is to factory restore the firewall which essentially wipes the configuration, unless you have Panorama and it still connects? To answer your questions:
1. Is our planned approach the best practice for recovering from lost access on the primary firewall in an HA setup?
I would take a similar action.
2. Are there any additional precautions or commands we should consider during manual failover and reboot?
Precautions, since the config has not synced in a long time, there could be traffic that is blocked.
CAUTION on resetting since the everything will be lost: https://docs.paloaltonetworks.com/ngfw/administration/firewall-administration/reset-the-firewall-to-...
3. Given the config drift, how can we best ensure synchronization without impacting live traffic?
It can only be performed from the active unit unfortunately.
4. Any known issues with very long uptime on Palo Alto firewalls causing credential/access problems?
I do not know of any however you can go through the release notes.
5. Are there alternative methods to regain access to the primary firewall that we might have missed, IS there any logs we can fetch to confirm where is the issue?
If you are getting logs from the active unit, it should show failed logins to the management interface. No other methods exist if you dont have the password.
Best of luck!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

