- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-24-2025 07:08 AM
Hi folks,
We have panorama and few pairs to managed firewalls being managed by panorama,
Under the Templates, created CSR and imported the signed CA and pushed it to specific template firewall(say FW01-active), the managed firewall local configurations displays the new certificate, however, on the FW02-passive one the certificate did not sync.
Do we need to separately push to FW02 template, by creating csr and same procedure? since its the vpn service certificate, it should sync from the active-FW01.
Note: Templates care configured for each firewall separate (eg: FW01-Template ; FW02 Template so on)
09-24-2025 02:51 PM
Hello @zaidshaikh
thanks for post.
Based on documentation: What Doesn't Sync in Active/Passive HA? most of the certificates and certificate related configuration does not sync in HA deployment. It specifically does not call out a certificate used for VPN, however personally I believe it is a root cause. I would add the certificate to the Template associated with FW02.
Kind Regards
Pavel
09-28-2025 02:55 AM
Hi Pavel,
Thank you for the response.
Presently the panorama is provisioned to managed 4 pairs of firewall, each pair is in A-P. What i found is that for each firewall let say FW01-Active has a individual Template and Template stack similarly for FW02-passive has individual T and TS.
Now with regards to s2s vpn cert based authenticate, i want to know if i generate a csr from each firewall template with similar CN: contoso.abc.com and import it into each firewall Template and Push.
Will the VPN will work after failover is trigerred? when old passive FW02 becomes new active? Assuming that similar CN will suffice for th tunnel to get establish with no issues.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!