How to configure or change the Master Key on a High Availability (HA) pair of firewalls
Objective
- Create a new Master Key on a High Availability (HA) pair of firewalls
- Change/Modify the existing Master Key on a pair of firewalls in a HA group
Environment
- PAN-OS 8.x, 9.x and 10.x
- High Availability (HA)
- Master Key
Procedure
*One important caveat when working with a HA pair and the Master Key is to turn off Config Sync on both firewalls.
Note that a config mismatch between the two HA devices while their master key doesn't match.
HA state (active/passive/etc) will not be affected by master key mismatch, but it is checked and logged when mismatch occurs. Disabling HA config sync is vital before configuring/changing master key. This operation should be completed as quickly as possible on the two devices to get the syncing operations back online. User should always double check the config sync status (HA dashboard) after re-enabling config sync.
- On both the Active and Passive firewalls, clear the Enable Config Sync checkbox
- Commit the configuration on both firewalls
- Configure the Master Key on the Active firewall
Note: If you are changing the Master Key then you will need the Current Master Key. If the Current Master Key is not known then a factory reset will need to be performed to restore the default Master Key.
- Click "OK". This will apply the Master Key immediately after, encrypting parts of the the configuration file
- Repeat steps 3 and 4 on the Passive firewall
- Re-enable Config Sync on both firewalls starting with the Active firewall
GUI: Device > High Availability > General > Setup
Note: Commit the configuration after re-enabling Config Sync on both firewalls
Additional Information
Per PAN-OS Administrator's Guide:
The master key must be identical on each firewall in the HA pair, but you must manually enter it on each firewall (Device > Master Key and Diagnostics).
Before changing the master key, you must disable config sync on both peers (Device > High Availability > General > Setup and clear the Enable Config Sync check box) and then re-enable it after you change the keys.