Troubleshooting master key deployment issues coming from Panorama
18984
Created On 02/09/19 04:08 AM - Last Modified 03/22/19 20:31 PM
Symptom
On the Panorama, check master key state for all managed devices / collectors / WildFire appliances / WildFire clusters:
- Panorama > Managed Devices
- Panorama > Managed Collectors
- Panorama > Managed WildFire Appliances
Last master key push is showing as "Failed"
Environment
- Panorama
- Firewall
- Master key
- PAN-OS 9.0
Cause
When a master key is added, a commit needs to be performed successfully before hand on the target device. This means commit validation errors need to be resolved before pushing a master key. Upon successful push of a master key, the device will then commit the configuration with encryption of all passwords and private keys
Resolution
Master key deployment operation fails, check the job details for the reason:
Additional Information
Refer to the 9.0 PAN-OS® New Features Guide for more information
https://docs.paloaltonetworks.com/pan-os/9-0/pan-os-new-features.html