- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
07-29-2026 05:13 AM
Hi,
I have a weird issue on a cluster of two firewalls on active/active mode.
Yesterday I tried to commit a small change on our policy, it was OK on the primary but it de-sync the secondary so I tried to sync to peer manually with no luck.
On the secondary I tried to commit localy and I had this error :
Unable to generate IKE VPN transform(Module: ikemgr)
client ikemgr phase 1 failure
Commit failed
I also tried to load an old conf and commit: same issue
I still had the gui but in cli, the connection with local and ldaps accounts was KO (I had the prompt but the fw rejected the connection). On the dashboard the HA was healthy, there were only the sync issue.
I rebooted the firewall and now I lost the gui access.
On the primary it seems that only the HA3 is up, HA1 and HA2 are down, peer is unknown.
And today I'm not able to commit on the primary with the same kind of issue as the secondary:
Unable to generate IKE VPN transform(Module: ikemgr)
client ikemgr phase 1 failure
Commit failed
Also, we cannot log on ssh like the secondary before the reboot.
I didn't use the ipsec module, there is no specific ike gateways, ipsec crypto or ike crypto profile. We do not use this cluster for ipsec connectivity.
Thanks for your help guys
Regards,
Ben
07-29-2026 05:18 AM
I forgot something, even a techsupport failed..
I will try tomorrow morning to have console access and try to execute some commands to understand what's happening
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!

