<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GP Certificate CN Mismatch issue when adding on more new Global Protect Gateway/Portal in GlobalProtect Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-certificate-cn-mismatch-issue-when-adding-on-more-new-global/m-p/475944#M2624</link>
    <description>&lt;P data-unlink="true"&gt;&lt;SPAN&gt;I have two PA-820 operating in Active/Passive HA mode. The WAN set up is a dual ISP connection to a single ISP which are configured using BGP. I was adding a new Global Protect Gateway and portal that is segregated from the existing one to connect separate group of users. Separate domain name and public IP with standalone SSL Certificate created for each on LetsEncrypt. The Palo Alto model is PA820 in HA Active-Passive mode. Its is connected through two leased-lines to a single ISP. So previously the working GP was&amp;nbsp;&lt;/SPAN&gt;aa.test.com&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;with public IP of &lt;U&gt;1.2.3.4&lt;/U&gt;, and the new domain name is&amp;nbsp;&lt;/SPAN&gt;&lt;U&gt;bb.test.com&lt;/U&gt;&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;with an public IP configured as &lt;U&gt;5.6.7.8.&lt;/U&gt; Totally segregated. Although everything is set up by the book, we are having a certificate error whenever someone tries to connect to the new GP&amp;nbsp;&lt;/SPAN&gt;bb.test.com&amp;nbsp;&lt;SPAN&gt;. The certificate error is happening with certificate of the old GP&amp;nbsp;&lt;/SPAN&gt;aa.test.com&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;being applied on to&amp;nbsp;&lt;/SPAN&gt;bb.test.com&amp;nbsp;&lt;SPAN&gt;. This is delaying the clients who are waiting to connect through the new portal/GW.&amp;nbsp;&lt;BR /&gt;The things I&amp;nbsp;have checked before coming to this forum,&lt;BR /&gt;1. I have used a FQDN when configuring the Agent&amp;gt;External Gateway and the correct GP certificate is applied on their respective GP Portal/Gateway&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2. The Interface IP is static so I have not used loopback IP, correct me if I am wrong here that I need to use a dummy loopback IP instead of the interface IP while the interface IPs are statically set.&lt;BR /&gt;3. The configuration for the GP portal/GW is correct and there is no configuration mix up/overlap between the two GW/Portals set up. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;4. Separate public IP is used for each and different FQDN as well. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;5. Separate Cert is created using letsencrypt and uploaded on the CertMgmt&amp;gt;Certificate.&lt;/SPAN&gt;&lt;/P&gt;&lt;P data-unlink="true"&gt;&lt;SPAN&gt;6. Separate tunnel is created and each tunnel is used for each GW/Portal(the new and the old one).&lt;BR /&gt;Brief recap of the issue:&lt;BR /&gt;Here is a quick recap of our session:&lt;BR /&gt;=================================&lt;BR /&gt;- The issue is with a newly configured Global Protect&lt;BR /&gt;- The issue which you are facing is that the newly configured gp configuration is taking an old certificate.&lt;BR /&gt;- The portal URL for Old is&amp;nbsp;aa.test.com&amp;nbsp;, and the New one is bb.test.com&amp;nbsp;&lt;BR /&gt;- The error that I am getting on client's pc is that The certificate CN name mismatch. The certificate is not issued to&amp;nbsp;bb.test.com.&amp;nbsp;&lt;BR /&gt;- The certificate profile and GP configuration has been verified with PA Support Engineer too.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;&lt;SPAN&gt;You kind support is appreciated, please.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 26 Mar 2022 08:40:32 GMT</pubDate>
    <dc:creator>sisayfe</dc:creator>
    <dc:date>2022-03-26T08:40:32Z</dc:date>
    <item>
      <title>GP Certificate CN Mismatch issue when adding on more new Global Protect Gateway/Portal</title>
      <link>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-certificate-cn-mismatch-issue-when-adding-on-more-new-global/m-p/475944#M2624</link>
      <description>&lt;P data-unlink="true"&gt;&lt;SPAN&gt;I have two PA-820 operating in Active/Passive HA mode. The WAN set up is a dual ISP connection to a single ISP which are configured using BGP. I was adding a new Global Protect Gateway and portal that is segregated from the existing one to connect separate group of users. Separate domain name and public IP with standalone SSL Certificate created for each on LetsEncrypt. The Palo Alto model is PA820 in HA Active-Passive mode. Its is connected through two leased-lines to a single ISP. So previously the working GP was&amp;nbsp;&lt;/SPAN&gt;aa.test.com&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;with public IP of &lt;U&gt;1.2.3.4&lt;/U&gt;, and the new domain name is&amp;nbsp;&lt;/SPAN&gt;&lt;U&gt;bb.test.com&lt;/U&gt;&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;with an public IP configured as &lt;U&gt;5.6.7.8.&lt;/U&gt; Totally segregated. Although everything is set up by the book, we are having a certificate error whenever someone tries to connect to the new GP&amp;nbsp;&lt;/SPAN&gt;bb.test.com&amp;nbsp;&lt;SPAN&gt;. The certificate error is happening with certificate of the old GP&amp;nbsp;&lt;/SPAN&gt;aa.test.com&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;being applied on to&amp;nbsp;&lt;/SPAN&gt;bb.test.com&amp;nbsp;&lt;SPAN&gt;. This is delaying the clients who are waiting to connect through the new portal/GW.&amp;nbsp;&lt;BR /&gt;The things I&amp;nbsp;have checked before coming to this forum,&lt;BR /&gt;1. I have used a FQDN when configuring the Agent&amp;gt;External Gateway and the correct GP certificate is applied on their respective GP Portal/Gateway&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2. The Interface IP is static so I have not used loopback IP, correct me if I am wrong here that I need to use a dummy loopback IP instead of the interface IP while the interface IPs are statically set.&lt;BR /&gt;3. The configuration for the GP portal/GW is correct and there is no configuration mix up/overlap between the two GW/Portals set up. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;4. Separate public IP is used for each and different FQDN as well. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;5. Separate Cert is created using letsencrypt and uploaded on the CertMgmt&amp;gt;Certificate.&lt;/SPAN&gt;&lt;/P&gt;&lt;P data-unlink="true"&gt;&lt;SPAN&gt;6. Separate tunnel is created and each tunnel is used for each GW/Portal(the new and the old one).&lt;BR /&gt;Brief recap of the issue:&lt;BR /&gt;Here is a quick recap of our session:&lt;BR /&gt;=================================&lt;BR /&gt;- The issue is with a newly configured Global Protect&lt;BR /&gt;- The issue which you are facing is that the newly configured gp configuration is taking an old certificate.&lt;BR /&gt;- The portal URL for Old is&amp;nbsp;aa.test.com&amp;nbsp;, and the New one is bb.test.com&amp;nbsp;&lt;BR /&gt;- The error that I am getting on client's pc is that The certificate CN name mismatch. The certificate is not issued to&amp;nbsp;bb.test.com.&amp;nbsp;&lt;BR /&gt;- The certificate profile and GP configuration has been verified with PA Support Engineer too.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;&lt;SPAN&gt;You kind support is appreciated, please.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 26 Mar 2022 08:40:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/globalprotect-discussions/gp-certificate-cn-mismatch-issue-when-adding-on-more-new-global/m-p/475944#M2624</guid>
      <dc:creator>sisayfe</dc:creator>
      <dc:date>2022-03-26T08:40:32Z</dc:date>
    </item>
  </channel>
</rss>

