Every firewall and Panorama management server
has a default master key that encrypts all the private keys and
passwords in the configuration to secure them (such as the private
key used for SSL Forward Proxy Decryption).
Change
the default master key as soon as possible to ensure that you use
a unique master key for encryption.
In a high availability
(HA) configuration, you must use the same master key on both firewalls
because the master key is not synchronized across HA peers. Otherwise, HA
synchronization will not work properly.
If you are using Panorama
to manage your firewalls, you can configure the same master key
on Panorama and all managed firewalls or configure a unique master
key for each managed firewall. For managed firewalls in an HA configuration,
you must configure the same master key for each HA peer. See
Manage the Master Key from Panorama if
the firewall is managed by a Panorama™ management server.