Forum Discussion

jaikumar_f5_226's avatar
jaikumar_f5_226
Icon for Nimbostratus rankNimbostratus
May 21, 2017

FIPS SO & DO pwd forgotten

Hey Folks,

 

Need your inputs again :)

 

I have a HA FIPS pair 8900 device, one of the F5 got faulty and just got RMA'ed. But I'm not having the SO & DO pwd now. Also I'm unable to load the UCS because of it. What route should I follow now ? Should I reset a new set of SO & DO pwds on scheduled window ?

 

2 Replies

  • JG's avatar
    JG
    Icon for Cumulonimbus rankCumulonimbus

    When you replace one system of a failover pair, instead of restoring the configuration by installing the UCS archive, F5 recommends that you configure basic networking on the replacement unit and synchronize the configuration from its peer. Since the master key is shared between units of a redundant pair, the configuration synchronization process will synchronize the original master key to the newly-installed device.

    From: K9420: Installing a UCS file containing an encrypted passphrase.

  • Anesh's avatar
    Anesh
    Icon for Cirrostratus rankCirrostratus

    you can try the methods outlined under section "Implementing a replacement unit in a device group after a system failure" in this Article