cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who rated this post

L0 Member

I had already tried a commit force and it changed nothing.  Ultimately, I was able to convince Palo Alto to handle my case directly since my provider is still dragging their feet.

Indeed Palo Alto support must go through a challenge/response process to gain root access to the device in order to clear out the old cert and generate a new one.  I asked and this seems to be a regular problem.  I'm not sure why Palo Alto wouldn't prioritize a proper fix for this issue both to alleviate support load and to enable their customers to continue working.  Since the device certificate was preventing a successful CIE sync, all VPN user/group addition/removals were blocked until we could get support's attention to fix the issue.  This should not be an acceptable bug to leave in the product.

View solution in original post

Who rated this post