<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Certificate to secure  100 plus SD WAN PANFW management interface for webui in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/certificate-to-secure-100-plus-sd-wan-panfw-management-interface/m-p/576730#M2612</link>
    <description>&lt;P&gt;Thank you Iain. SSL profile works not only for management interface but other webui sessions. I will test.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Daniel&lt;/P&gt;</description>
    <pubDate>Fri, 09 Feb 2024 01:33:59 GMT</pubDate>
    <dc:creator>Daniel_Li</dc:creator>
    <dc:date>2024-02-09T01:33:59Z</dc:date>
    <item>
      <title>Certificate to secure  100 plus SD WAN PANFW management interface for webui</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/certificate-to-secure-100-plus-sd-wan-panfw-management-interface/m-p/574579#M2529</link>
      <description>&lt;P&gt;All&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I plan to secure web interface for management of PANFW. we use data plane IP to manage all FWs.&amp;nbsp; Is there way to deploy certs to each PAN via Panorama or it has to be done one by one. If any one did this before Please help and share&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Daniel&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2024 16:34:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/certificate-to-secure-100-plus-sd-wan-panfw-management-interface/m-p/574579#M2529</guid>
      <dc:creator>Daniel_Li</dc:creator>
      <dc:date>2024-01-26T16:34:14Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate to secure  100 plus SD WAN PANFW management interface for webui</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/certificate-to-secure-100-plus-sd-wan-panfw-management-interface/m-p/575922#M2579</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/14775"&gt;@Daniel_Li&lt;/a&gt;&amp;nbsp;- do you have an enterprise CA that you can leverage?&amp;nbsp; If so, and if you're fine with all of the firewalls having the same certificate on them, you could use a SAN certificate, or a wildcard certificate.&amp;nbsp; The instructions &lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/certificate-management/obtain-certificates/import-a-certificate-and-private-key" target="_self"&gt;here&lt;/A&gt; may help you.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you need each device to have its own certificate, you may have some luck in automating the process via the CLI, but I'm not aware of any existing supported scripts to do this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 00:13:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/certificate-to-secure-100-plus-sd-wan-panfw-management-interface/m-p/575922#M2579</guid>
      <dc:creator>iarobertson</dc:creator>
      <dc:date>2024-02-05T00:13:31Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate to secure  100 plus SD WAN PANFW management interface for webui</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/certificate-to-secure-100-plus-sd-wan-panfw-management-interface/m-p/576638#M2608</link>
      <description>&lt;P&gt;Thank you Iain for your kind reply. We have Microsoft CA. Will try the link. Other question you could help answer. we are using loopback interface for webui access and managed by Panorama (not using management plane interface). How to implement SSL profile to loopback interface to secure it&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 16:20:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/certificate-to-secure-100-plus-sd-wan-panfw-management-interface/m-p/576638#M2608</guid>
      <dc:creator>Daniel_Li</dc:creator>
      <dc:date>2024-02-08T16:20:45Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate to secure  100 plus SD WAN PANFW management interface for webui</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/certificate-to-secure-100-plus-sd-wan-panfw-management-interface/m-p/576727#M2610</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/14775"&gt;@Daniel_Li&lt;/a&gt;&amp;nbsp;- please refer to &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFGCA0" target="_self"&gt;this&lt;/A&gt; knowledgebase article; once SSL is set up, it is valid for all WebUI sessions.&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2024 00:44:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/certificate-to-secure-100-plus-sd-wan-panfw-management-interface/m-p/576727#M2610</guid>
      <dc:creator>iarobertson</dc:creator>
      <dc:date>2024-02-09T00:44:37Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate to secure  100 plus SD WAN PANFW management interface for webui</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/certificate-to-secure-100-plus-sd-wan-panfw-management-interface/m-p/576730#M2612</link>
      <description>&lt;P&gt;Thank you Iain. SSL profile works not only for management interface but other webui sessions. I will test.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Daniel&lt;/P&gt;</description>
      <pubDate>Fri, 09 Feb 2024 01:33:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/certificate-to-secure-100-plus-sd-wan-panfw-management-interface/m-p/576730#M2612</guid>
      <dc:creator>Daniel_Li</dc:creator>
      <dc:date>2024-02-09T01:33:59Z</dc:date>
    </item>
    <item>
      <title>Re: Certificate to secure  100 plus SD WAN PANFW management interface for webui</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/certificate-to-secure-100-plus-sd-wan-panfw-management-interface/m-p/577165#M2648</link>
      <description>&lt;P&gt;Iain&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I was told by Tech that SSL profile can not be applied to loopback interface in the data plane. Only to management interface in the management&lt;/P&gt;
&lt;P&gt;plane. I have not tested but it seems to be correct technically&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Daniel&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2024 20:26:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/certificate-to-secure-100-plus-sd-wan-panfw-management-interface/m-p/577165#M2648</guid>
      <dc:creator>Daniel_Li</dc:creator>
      <dc:date>2024-02-13T20:26:00Z</dc:date>
    </item>
  </channel>
</rss>

