<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PANOS Global Protect Azure SAML w/ Self-Signed Certifcate on Firewall in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/panos-global-protect-azure-saml-w-self-signed-certifcate-on/m-p/1261998#M7097</link>
    <description>&lt;P&gt;Based on my understanding, you have created a Global Protect Portal on one PA-VM &amp;amp; Gateway on the other PA-VM. If yes, this normally works as this is more common architecture when you have multi-site VPN. Only concerning part is use of self-signed certificate. Is this your internal VPN or test VPN. Because client should trust the certificate else they will get self-signed certificate related errors.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 17 Aug 2026 09:11:06 GMT</pubDate>
    <dc:creator>SutareMayur</dc:creator>
    <dc:date>2026-08-17T09:11:06Z</dc:date>
    <item>
      <title>PANOS Global Protect Azure SAML w/ Self-Signed Certifcate on Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/panos-global-protect-azure-saml-w-self-signed-certifcate-on/m-p/1259710#M7038</link>
      <description>&lt;P&gt;Looking to see if anyone has done the above configuration.&amp;nbsp; Essentially 2 sets of firewalls, 2 locations, managed in Panorama.&amp;nbsp; I created the portal on 1 set, using a self-signed certificate on the firewall (used the PA-VM as the CA and then issued itself a certificate).&amp;nbsp; Created 1 gateway on the local VM, then planned to issue the remote VM a certificate as well and then use that on the gateway on that firewall.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the Azure side, I set this up as a standard SAML integration, I just uploaded the certificate (the one that was signed by the CA) into Azure.&amp;nbsp; I should be able to test in the next few days but wanted to see if anyone had any feedback.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2026 17:19:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/panos-global-protect-azure-saml-w-self-signed-certifcate-on/m-p/1259710#M7038</guid>
      <dc:creator>DJ_1924</dc:creator>
      <dc:date>2026-07-22T17:19:29Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS Global Protect Azure SAML w/ Self-Signed Certifcate on Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/panos-global-protect-azure-saml-w-self-signed-certifcate-on/m-p/1261998#M7097</link>
      <description>&lt;P&gt;Based on my understanding, you have created a Global Protect Portal on one PA-VM &amp;amp; Gateway on the other PA-VM. If yes, this normally works as this is more common architecture when you have multi-site VPN. Only concerning part is use of self-signed certificate. Is this your internal VPN or test VPN. Because client should trust the certificate else they will get self-signed certificate related errors.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Aug 2026 09:11:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/panos-global-protect-azure-saml-w-self-signed-certifcate-on/m-p/1261998#M7097</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2026-08-17T09:11:06Z</dc:date>
    </item>
    <item>
      <title>Re: PANOS Global Protect Azure SAML w/ Self-Signed Certifcate on Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/panos-global-protect-azure-saml-w-self-signed-certifcate-on/m-p/1262309#M7102</link>
      <description>&lt;P&gt;Thanks for replying.&amp;nbsp; Using a self-signed certificate w/ the PA-VM as the CA, then creating a certificate w/ the FQDN using itself as the one that signs it.&amp;nbsp; Imported that certificate into Azure and set the client to trust the certificate so no warnings (plan is to push the certificate and GP client out via MDM).&amp;nbsp; This seemed to work ok and testing has been successful.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Trying to integrate the 2nd PA-VM now.&amp;nbsp; The setup went mostly the same, but trying to figure out the certificates for the 2nd firewall.&amp;nbsp; Would i need to export the root from the first firewall and issue the 2nd certificate from that firewall as well and then export them and import them into the 2nd unit?&amp;nbsp; Then setup a 2nd Enterprise Application in Azure using that new certificate?&amp;nbsp; Same for the portal to gateway cookie certificate?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There will be public FQDNs for both sites&amp;nbsp; but at the moment the Public CA that is being used doesn't offer ACME and the goal was to be able to extend the certificate expiration dates to account for the looming changes.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Aug 2026 13:00:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/panos-global-protect-azure-saml-w-self-signed-certifcate-on/m-p/1262309#M7102</guid>
      <dc:creator>DJ_1924</dc:creator>
      <dc:date>2026-08-19T13:00:16Z</dc:date>
    </item>
  </channel>
</rss>

