hello everyone, I lost SSH access to my PA-3020 passive firewall on mgmt. interface.. I can access it via GUI. for Active Firewall, both SSH and GUI are OK. I think it happened after I did fixing weak ciphers and keys on mgmt. interface. interface for SSH access. I did the following procedure on both active/passive FW. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000PN5bCAG and I found the Palo recommended solution below, but I could not able to access the device console currently. Solution: On secondary FW, turn off SSH from the WebUI. Log in through the console, first delete the existing configuration and then make the cipher changes again. Restart the service "set ssh service-restart mgmt" Then turned on SSH from the WebUI Or You can change the SSH related configuration on both FW simultaneously and restart SSH service on management together. https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000HAsiCAG is there any way to fix the issue by remote? - can we fix by enabling telnet and access the device? - can we fix by rebooting passive device? - can we fix by running the following commands? > request high-availability sync-to-remote running-config (on Active) > set ssh service-restart mgmt (on Passive) Please suggest. Thank you.
... View more