<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global protect &amp;quot;certificate is not singed by CA&amp;quot; not allow to connect time to time in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/global-protect-quot-certificate-is-not-singed-by-ca-quot-not/m-p/563023#M2000</link>
    <description>&lt;P&gt;The recommendation (based on my understanding) is to ensure that both siteA and siteB are using publicly signed certificates for the Global Protect.&amp;nbsp; Because you do not mention it, I am not sure to presume they are publicly signed.&amp;nbsp; I am not sure if you are using 2 different portals (siteA portal with 2 gateways.. siteA and siteB?).&amp;nbsp; There are so many variables, that is makes sense to open a TAC web case to get this properly troubleshot.&lt;/P&gt;</description>
    <pubDate>Tue, 24 Oct 2023 22:37:03 GMT</pubDate>
    <dc:creator>S.Cantwell</dc:creator>
    <dc:date>2023-10-24T22:37:03Z</dc:date>
    <item>
      <title>Global protect "certificate is not singed by CA" not allow to connect time to time</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/global-protect-quot-certificate-is-not-singed-by-ca-quot-not/m-p/556686#M1800</link>
      <description>&lt;P&gt;We have global protect version 6.1.1-5&lt;/P&gt;
&lt;P&gt;When we connect to the GP it's working fine. Once we connect to another firewall's GP and disconnected from it and try to connect again to same firewall then we get the error "certificate is not singed by CA"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For example :&lt;/P&gt;
&lt;P&gt;Let's assume Site A is having a firewall cluster and Site B is having a firewall cluster. If we connect to Site A firewall GP connects successful and then if we disconnect from site A and connect to site B then also GP connects without any issues. If we try to disconnect from site B and connect to site A again then we are getting the above mentioned error. &lt;BR /&gt;&lt;BR /&gt;Any solutions for this ?&lt;/P&gt;</description>
      <pubDate>Wed, 06 Sep 2023 07:17:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/global-protect-quot-certificate-is-not-singed-by-ca-quot-not/m-p/556686#M1800</guid>
      <dc:creator>Navaneetharaj</dc:creator>
      <dc:date>2023-09-06T07:17:59Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect "certificate is not singed by CA" not allow to connect time to time</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/global-protect-quot-certificate-is-not-singed-by-ca-quot-not/m-p/563023#M2000</link>
      <description>&lt;P&gt;The recommendation (based on my understanding) is to ensure that both siteA and siteB are using publicly signed certificates for the Global Protect.&amp;nbsp; Because you do not mention it, I am not sure to presume they are publicly signed.&amp;nbsp; I am not sure if you are using 2 different portals (siteA portal with 2 gateways.. siteA and siteB?).&amp;nbsp; There are so many variables, that is makes sense to open a TAC web case to get this properly troubleshot.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Oct 2023 22:37:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/global-protect-quot-certificate-is-not-singed-by-ca-quot-not/m-p/563023#M2000</guid>
      <dc:creator>S.Cantwell</dc:creator>
      <dc:date>2023-10-24T22:37:03Z</dc:date>
    </item>
  </channel>
</rss>

