PA-5450 chassis replacement causes WildFire registration failure

PA-5450 chassis replacement causes WildFire registration failure

9584
Created On 06/07/23 01:11 AM - Last Modified 10/28/25 02:20 AM


Symptom


  • After replacing the PA-5450 chassis by RMA, WildFire registration failure messages are seen in the system log (show log system).
WildFire registration failed. Mismatched Serial number in certificate and payload.
  • When executing "request certificate fetch" followed by "show device-certificate status", it shows the certificate is valid, but "Last fetched info:" has "Invalid request: input chassis and MPC are not associated together."
admin@PA-5450(passive)> show device-certificate status

Device Certificate information:
Current device certificate status: Valid   
Not valid before: 2023/04/29 18:33:55 JST
Not valid after: 2023/07/29 18:33:55 JST
Last fetched timestamp: 2023/05/18 14:13:54 JST
Last fetched status: failure
Last fetched info: Failed to fetch device certificate.
Invalid request: input chassis and MPC are not associated together.    


Environment


  • Palo Alto PA-5450 Firewall
  • Supported PAN-OS
  • Hardware (chassis) is replaced


Cause


  • PA-5450 chassis and MPC association is recorded on our License database. 
  • After replacing the chassis or MPC, resetting the association is needed to fetch the device certificate again.


Resolution


Open a  Support Case to solve this symptom.

Actions
  • Print
  • Copy Link

    https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000bpxOCAQ&lang=en_US%E2%80%A9&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail&refURL=http%3A%2F%2Fknowledgebase.paloaltonetworks.com%2FKCSArticleDetail

Choose Language