<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How check NGFW valid for April 2024 Cert Advisory in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-check-ngfw-valid-for-april-2024-cert-advisory/m-p/580126#M2812</link>
    <description>&lt;P&gt;Provided that you have remediated the expired root certificate, yes.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As a reminder, you have 3 options:&lt;/P&gt;
&lt;P&gt;1. upgrade to the correct PAN-OS version (see link below)&lt;/P&gt;
&lt;P&gt;2. update the content to at least 8795 and then reboot&lt;/P&gt;
&lt;P&gt;3. install custom certificates&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;More details here&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/customer-advisories/additional-pan-os-certificate-expirations-and-new-comprehensive/ta-p/572158" target="_blank"&gt;https://live.paloaltonetworks.com/t5/customer-advisories/additional-pan-os-certificate-expirations-and-new-comprehensive/ta-p/572158&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;--Richard&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2024 23:05:27 GMT</pubDate>
    <dc:creator>rdumoulin</dc:creator>
    <dc:date>2024-03-12T23:05:27Z</dc:date>
    <item>
      <title>How check NGFW valid for April 2024 Cert Advisory</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-check-ngfw-valid-for-april-2024-cert-advisory/m-p/576101#M2583</link>
      <description>&lt;P&gt;Regarding the Certificate advisory for April 2024 and November 2024, if doing option 1, have content update and doing a reboot.&lt;/P&gt;
&lt;P&gt;This being good enough for the April 2024 deadline. How can you verify on the Panorama or NGFW that you are valid?&amp;nbsp; The commands in the advisory FAQ 9, only work if you do Option 2 and upgrade to the recommended hotfix.&lt;/P&gt;
&lt;P&gt;If there is no method for the user to verify they can safely pass the April 2024 deadline, then i would assume you would have to call TAC to go into root to confirm that your NGFW is patched to pass the April 2024 deadline, otherwise its wishful thinking the day after April 7, 2024&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 20:54:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-check-ngfw-valid-for-april-2024-cert-advisory/m-p/576101#M2583</guid>
      <dc:creator>RussellYan</dc:creator>
      <dc:date>2024-02-05T20:54:41Z</dc:date>
    </item>
    <item>
      <title>Re: How check NGFW valid for April 2024 Cert Advisory</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-check-ngfw-valid-for-april-2024-cert-advisory/m-p/576115#M2584</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/240665"&gt;@RussellYan&lt;/a&gt;&amp;nbsp;- if you're taking Option 1, being the content update and reboot, there is no specific command that you can use to confirm you've completed remediation.&amp;nbsp; As you've correctly identified, this new command is available after a hotfix or upgrade per Option 2.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The best advice I can give is that you should check to see that the most recent reboot time is more recent than the installation time of the content update.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 22:23:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-check-ngfw-valid-for-april-2024-cert-advisory/m-p/576115#M2584</guid>
      <dc:creator>iarobertson</dc:creator>
      <dc:date>2024-02-05T22:23:40Z</dc:date>
    </item>
    <item>
      <title>Re: How check NGFW valid for April 2024 Cert Advisory</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-check-ngfw-valid-for-april-2024-cert-advisory/m-p/576118#M2585</link>
      <description>&lt;P&gt;Thank you lain. Am i to also assume, a TAC engineer with root access would also NOT be able to confirm before (remediation is installed besides the Content Version number) or after a reboot, that i have the remediation activated?&lt;/P&gt;
&lt;P&gt;Russ&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2024 23:30:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-check-ngfw-valid-for-april-2024-cert-advisory/m-p/576118#M2585</guid>
      <dc:creator>RussellYan</dc:creator>
      <dc:date>2024-02-05T23:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: How check NGFW valid for April 2024 Cert Advisory</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-check-ngfw-valid-for-april-2024-cert-advisory/m-p/576177#M2587</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/240665"&gt;@RussellYan&lt;/a&gt;&amp;nbsp;- I can't confirm that I'm afraid, I'm not aware of any commands that TAC might be able to run to validate.&amp;nbsp; In turn it would be safer to assume there exists no such commands.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Feb 2024 02:37:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-check-ngfw-valid-for-april-2024-cert-advisory/m-p/576177#M2587</guid>
      <dc:creator>iarobertson</dc:creator>
      <dc:date>2024-02-06T02:37:17Z</dc:date>
    </item>
    <item>
      <title>Re: How check NGFW valid for April 2024 Cert Advisory</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-check-ngfw-valid-for-april-2024-cert-advisory/m-p/580119#M2809</link>
      <description>&lt;P&gt;Hi Everyone,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;May I know if we haven’t reboot Palo Alto device before 7 April, what is the consequence? What can we do to fix it after 7 April?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2024 21:26:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-check-ngfw-valid-for-april-2024-cert-advisory/m-p/580119#M2809</guid>
      <dc:creator>WilsonWu</dc:creator>
      <dc:date>2024-03-12T21:26:51Z</dc:date>
    </item>
    <item>
      <title>Re: How check NGFW valid for April 2024 Cert Advisory</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-check-ngfw-valid-for-april-2024-cert-advisory/m-p/580124#M2810</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/306748"&gt;@WilsonWu&lt;/a&gt;&amp;nbsp;- if you haven't rebooted, you may lose Panorama management of any affected devices, and any Panorama log collectors may also cease to collect logs from affected devices.&amp;nbsp; Firewalls will continue to forward traffic.&lt;/P&gt;
&lt;P&gt;Installing the content update &amp;amp; rebooting after that date will remediate the issue.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2024 22:53:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-check-ngfw-valid-for-april-2024-cert-advisory/m-p/580124#M2810</guid>
      <dc:creator>iarobertson</dc:creator>
      <dc:date>2024-03-12T22:53:34Z</dc:date>
    </item>
    <item>
      <title>Re: How check NGFW valid for April 2024 Cert Advisory</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-check-ngfw-valid-for-april-2024-cert-advisory/m-p/580125#M2811</link>
      <description>&lt;P&gt;Hi Larobertson,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;So if I really haven’t reboot my Palo Alto before 7 April. Can I understand that I just need to reconnect my Palo Alto to panorama and reconnect any log collectors then it will be resume normal right?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2024 23:01:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-check-ngfw-valid-for-april-2024-cert-advisory/m-p/580125#M2811</guid>
      <dc:creator>WilsonWu</dc:creator>
      <dc:date>2024-03-12T23:01:07Z</dc:date>
    </item>
    <item>
      <title>Re: How check NGFW valid for April 2024 Cert Advisory</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-check-ngfw-valid-for-april-2024-cert-advisory/m-p/580126#M2812</link>
      <description>&lt;P&gt;Provided that you have remediated the expired root certificate, yes.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As a reminder, you have 3 options:&lt;/P&gt;
&lt;P&gt;1. upgrade to the correct PAN-OS version (see link below)&lt;/P&gt;
&lt;P&gt;2. update the content to at least 8795 and then reboot&lt;/P&gt;
&lt;P&gt;3. install custom certificates&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;More details here&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/customer-advisories/additional-pan-os-certificate-expirations-and-new-comprehensive/ta-p/572158" target="_blank"&gt;https://live.paloaltonetworks.com/t5/customer-advisories/additional-pan-os-certificate-expirations-and-new-comprehensive/ta-p/572158&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;--Richard&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2024 23:05:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-check-ngfw-valid-for-april-2024-cert-advisory/m-p/580126#M2812</guid>
      <dc:creator>rdumoulin</dc:creator>
      <dc:date>2024-03-12T23:05:27Z</dc:date>
    </item>
    <item>
      <title>Re: How check NGFW valid for April 2024 Cert Advisory</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-check-ngfw-valid-for-april-2024-cert-advisory/m-p/580127#M2813</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/306748"&gt;@WilsonWu&lt;/a&gt;&amp;nbsp;- you will need to take the remediation steps as described in the advisory.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That means you will need to at least apply Option 1 - content update + reboot, or alternatively Option 2 - hotfix release.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you do not do this before April 7 you may lose Panorama and log collector connectivity.&amp;nbsp; If you do not do this before April 7 you will need to take the steps described briefly above, and in more detail in the advisory, in order to reconnect.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2024 23:07:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-check-ngfw-valid-for-april-2024-cert-advisory/m-p/580127#M2813</guid>
      <dc:creator>iarobertson</dc:creator>
      <dc:date>2024-03-12T23:07:46Z</dc:date>
    </item>
    <item>
      <title>Re: How check NGFW valid for April 2024 Cert Advisory</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-check-ngfw-valid-for-april-2024-cert-advisory/m-p/580493#M2833</link>
      <description>&lt;P&gt;thanks for sharing....&amp;nbsp;&lt;A href="https://ncedcloud.fun/" target="_self"&gt;NC Cloud&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 04:52:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-check-ngfw-valid-for-april-2024-cert-advisory/m-p/580493#M2833</guid>
      <dc:creator>Sanchez78</dc:creator>
      <dc:date>2024-03-18T04:52:05Z</dc:date>
    </item>
    <item>
      <title>Re: How check NGFW valid for April 2024 Cert Advisory</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-check-ngfw-valid-for-april-2024-cert-advisory/m-p/580702#M2841</link>
      <description>&lt;P&gt;Dear all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you for everyone.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 02:54:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-check-ngfw-valid-for-april-2024-cert-advisory/m-p/580702#M2841</guid>
      <dc:creator>WilsonWu</dc:creator>
      <dc:date>2024-03-18T02:54:56Z</dc:date>
    </item>
    <item>
      <title>Re: How check NGFW valid for April 2024 Cert Advisory</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-check-ngfw-valid-for-april-2024-cert-advisory/m-p/582803#M2945</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/323965"&gt;@iarobertson&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I noticed that option 3 refers to a custom certificate. Is there a way to verify if the custom certificate has been successfully installed and working properly on Panorama and NGFW, aside from being &lt;EM&gt;'deployed'&lt;/EM&gt; status under panorama &amp;gt; manage device &amp;gt; summary and certificate column?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the link: &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000wo5WCAQ" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u000000wo5WCAQ&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2024 15:29:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-check-ngfw-valid-for-april-2024-cert-advisory/m-p/582803#M2945</guid>
      <dc:creator>JPatrickMillado</dc:creator>
      <dc:date>2024-04-05T15:29:58Z</dc:date>
    </item>
    <item>
      <title>Re: How check NGFW valid for April 2024 Cert Advisory</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-check-ngfw-valid-for-april-2024-cert-advisory/m-p/582804#M2946</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/302791"&gt;@JPatrickMillado&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="p-rich_text_section"&gt;from&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG data-stringify-type="bold"&gt;Panorama&lt;/STRONG&gt;:&lt;/DIV&gt;
&lt;OL class="p-rich_text_list p-rich_text_list__ordered" data-stringify-type="ordered-list" data-indent="0" data-border="0"&gt;
&lt;LI data-stringify-indent="0" data-stringify-border="0"&gt;show devices connected | match yes\|Custom\|Certificate&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/LI&gt;
&lt;/OL&gt;
&lt;DIV class="p-rich_text_section"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;2.&amp;nbsp; show high-availability management-connection&lt;BR /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;3.&amp;nbsp; show log-collector all&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;&lt;SPAN&gt;1st commands is going to tell us if the Pano &amp;lt;-&amp;gt; FWs connections are using custom cert.... !get this output from Panorama and LCs&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;2nd command is to confirm the Pano HA (Pano &amp;lt;-&amp;gt; Pano) is using the Custom Certs.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;3rd Command&amp;nbsp; will tell us if the Pano &amp;lt;-&amp;gt; LCs connections are using&amp;nbsp; the Custom Certs.&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="p-rich_text_section"&gt;&lt;SPAN&gt;--Richard&lt;/SPAN&gt;&lt;/DIV&gt;</description>
      <pubDate>Fri, 05 Apr 2024 15:39:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-check-ngfw-valid-for-april-2024-cert-advisory/m-p/582804#M2946</guid>
      <dc:creator>rdumoulin</dc:creator>
      <dc:date>2024-04-05T15:39:54Z</dc:date>
    </item>
    <item>
      <title>Re: How check NGFW valid for April 2024 Cert Advisory</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-check-ngfw-valid-for-april-2024-cert-advisory/m-p/582808#M2947</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/273288"&gt;@rdumoulin&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Item 1 and 3 commands are working, except '&lt;SPAN&gt;show high-availability management-connection. It appears that this command is not supported by our device.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Appreciate this information&lt;span class="lia-unicode-emoji" title=":ok_hand:"&gt;👌&lt;/span&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 05 Apr 2024 16:03:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/how-check-ngfw-valid-for-april-2024-cert-advisory/m-p/582808#M2947</guid>
      <dc:creator>JPatrickMillado</dc:creator>
      <dc:date>2024-04-05T16:03:21Z</dc:date>
    </item>
  </channel>
</rss>

