<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Override url ocsp and responder ocsp global protect VPN in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/override-url-ocsp-and-responder-ocsp-global-protect-vpn/m-p/1257712#M6999</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/280315"&gt;@HAINVH&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;What have you tried so far?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;You should be able to host OCSP on an alternate interface instead of tying it to the management IP.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;A few things I would be mindful of:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL data-spread="false"&gt;
&lt;LI&gt;&lt;SPAN&gt;The interface should have an Interface Management Profile applied with &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;HTTP OCSP&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; enabled.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;The OCSP responder hostname/IP should resolve to the data-plane or loopback interface.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Routing and security policy need to allow the OCSP traffic.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 30 Jun 2026 01:18:10 GMT</pubDate>
    <dc:creator>JayGolf</dc:creator>
    <dc:date>2026-06-30T01:18:10Z</dc:date>
    <item>
      <title>Override url ocsp and responder ocsp global protect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/override-url-ocsp-and-responder-ocsp-global-protect-vpn/m-p/1257667#M6998</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;present, i have VPN global protec&lt;/P&gt;
&lt;P&gt;Authentication two factor with certificate and radius, by interface management&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The current setup is as follows:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;The Palo Alto firewall acts as both the gateway and the OCSP responder.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;The OCSP responder is configured to use the management IP address, and the OCSP Override URL also points to the management IP.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;Because certificate validation relies on the management IP, a failover to the HA peer causes certificate validation to fail. In addition, having only a single management link creates a potential single point of failure.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;To improve resiliency, I would like to use either a data-plane IP address or a loopback IP address as the OCSP responder, and configure the OCSP Override URL to point to that loopback or data-plane IP instead.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;However, I’ve tried several configurations without success.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Could you please help me understand how to achieve this?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;with 1000user i dont want create new all&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2026 14:56:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/override-url-ocsp-and-responder-ocsp-global-protect-vpn/m-p/1257667#M6998</guid>
      <dc:creator>HAINVH</dc:creator>
      <dc:date>2026-06-29T14:56:38Z</dc:date>
    </item>
    <item>
      <title>Re: Override url ocsp and responder ocsp global protect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/override-url-ocsp-and-responder-ocsp-global-protect-vpn/m-p/1257712#M6999</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/280315"&gt;@HAINVH&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;What have you tried so far?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;You should be able to host OCSP on an alternate interface instead of tying it to the management IP.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;A few things I would be mindful of:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL data-spread="false"&gt;
&lt;LI&gt;&lt;SPAN&gt;The interface should have an Interface Management Profile applied with &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;HTTP OCSP&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; enabled.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;The OCSP responder hostname/IP should resolve to the data-plane or loopback interface.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Routing and security policy need to allow the OCSP traffic.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2026 01:18:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/override-url-ocsp-and-responder-ocsp-global-protect-vpn/m-p/1257712#M6999</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2026-06-30T01:18:10Z</dc:date>
    </item>
  </channel>
</rss>

