ha sync failed my certificates - Flex 500 (not H)

Options
AMI
AMI image  Freshman Member
First Comment Friend Collector Third Anniversary
edited August 20 in Security

i cannot sync 2 FW's, always comes back with that - yet it shows succeeded in the gui, but i can see on the shell its not the actual config from the active unit.

[2026/8/20 12:16:39] sync.c:3660: Retrieving version Certificates for My CERT has succeeded

[2026/8/20 12:16:41] sync.c:3402: Retrieving Certificates for My CERT has failed

[2026/8/20 12:16:45] sync.c:3402: Retrieving Certificates for My CERT has failed

[2026/8/20 12:16:50] sync.c:3402: Retrieving Certificates for My CERT has failed

[2026/8/20 12:16:50] sync.c:4179: Device HA Sync has failed from 100.64.30.1 at 2026-08-20 12:16:50.
Please check log for details. (failed)

one thing to note, we added a cert (self-signed) for VPN - before that HA setup. (Standy unit had already gone through 2x fac default)

I could delete that and try the sync - but thats part of an active config and a live system

i set the port 8 interface to its default values, actually tried removing that cert, started manual sync from passive - still fails at the same spot.

Special note: It says successful everywhere in the gui and on the shell - but its a lie, the config is still the (at least partial) the old one / default - only the trace log show the truth

Accepted Solution

  • AMI
    AMI image  Freshman Member
    First Comment Friend Collector Third Anniversary
    Answer ✓
    Options

    A reset of the certificate store fixed the issue, but that has the effect that all non default certificates are deleted. In any case, this was the fix.

All Replies

  • Zyxel_Melen
    Zyxel_Melen image  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate
    Options

    Hi @AMI

    Could you collect the diagnostic file on both device? This will help us to check this issue.

    I will send you a private message for you to share the diagnostic file with us.

    Zyxel Melen


  • AMI
    AMI image  Freshman Member
    First Comment Friend Collector Third Anniversary
    Answer ✓
    Options

    A reset of the certificate store fixed the issue, but that has the effect that all non default certificates are deleted. In any case, this was the fix.