<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cluster FW Active-Pasive syncronize  certificate profile 10.1.9-h1 in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/cluster-fw-active-pasive-syncronize-certificate-profile-10-1-9/m-p/566889#M114546</link>
    <description>&lt;P&gt;Hello team&lt;/P&gt;
&lt;P&gt;I am deploying web auth with certificate&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewall-administration/manage-firewall-administrators/configure-administrative-accounts-and-authentication/configure-certificate-based-administrator-authentication-to-the-web-interface" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewall-administration/manage-firewall-administrators/configure-administrative-accounts-and-authentication/configure-certificate-based-administrator-authentication-to-the-web-interface&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;in an active - passive cluster, the problem is that the certificate profile is synchronized when I commit, which generates that I can only use one and so I can only access one of the nodes, any idea? it seems a bug but I have not found anything.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/high-availability/reference-ha-synchronization/what-settings-dont-sync-in-activepassive-ha" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/high-availability/reference-ha-synchronization/what-settings-dont-sync-in-activepassive-ha&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 23 Nov 2023 15:06:40 GMT</pubDate>
    <dc:creator>Alpalo</dc:creator>
    <dc:date>2023-11-23T15:06:40Z</dc:date>
    <item>
      <title>Cluster FW Active-Pasive syncronize  certificate profile 10.1.9-h1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cluster-fw-active-pasive-syncronize-certificate-profile-10-1-9/m-p/566889#M114546</link>
      <description>&lt;P&gt;Hello team&lt;/P&gt;
&lt;P&gt;I am deploying web auth with certificate&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewall-administration/manage-firewall-administrators/configure-administrative-accounts-and-authentication/configure-certificate-based-administrator-authentication-to-the-web-interface" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/9-1/pan-os-admin/firewall-administration/manage-firewall-administrators/configure-administrative-accounts-and-authentication/configure-certificate-based-administrator-authentication-to-the-web-interface&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;in an active - passive cluster, the problem is that the certificate profile is synchronized when I commit, which generates that I can only use one and so I can only access one of the nodes, any idea? it seems a bug but I have not found anything.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/high-availability/reference-ha-synchronization/what-settings-dont-sync-in-activepassive-ha" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-1/pan-os-admin/high-availability/reference-ha-synchronization/what-settings-dont-sync-in-activepassive-ha&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2023 15:06:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cluster-fw-active-pasive-syncronize-certificate-profile-10-1-9/m-p/566889#M114546</guid>
      <dc:creator>Alpalo</dc:creator>
      <dc:date>2023-11-23T15:06:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cluster FW Active-Pasive syncronize  certificate profile 10.1.9-h1</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/cluster-fw-active-pasive-syncronize-certificate-profile-10-1-9/m-p/566918#M114551</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192671"&gt;@Alpalo&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;Similar questions were asked before, please check the following post - &lt;A href="https://live.paloaltonetworks.com/t5/next-generation-firewall/how-to-use-certificate-for-secure-web-gui-access-ha-pair/m-p/566112" target="_blank"&gt;https://live.paloaltonetworks.com/t5/next-generation-firewall/how-to-use-certificate-for-secure-web-gui-access-ha-pair/m-p/566112&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;TL;DR - certificate is not synchronized so you need to import it separately on both members. However you &lt;U&gt;must&lt;/U&gt; use the same name (no cert CN, but name for the cert when importing it to the config). You can choose to use separate certificates with different CNs for each member, or single cert using SAN or wildcard.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2023 18:24:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/cluster-fw-active-pasive-syncronize-certificate-profile-10-1-9/m-p/566918#M114551</guid>
      <dc:creator>aleksandar.astardzhiev</dc:creator>
      <dc:date>2023-11-23T18:24:31Z</dc:date>
    </item>
  </channel>
</rss>

