<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IKEV2 w Cert - Wildcard peer for DN does not work. in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ikev2-w-cert-wildcard-peer-for-dn-does-not-work/m-p/1224243#M123709</link>
    <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/185085"&gt;@NSutfin&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;When you're configuring the IKE gateway have you made sure that your peer ID check is set to Wildcard and do you have the certification payload identification mismatch box checked at all? &lt;/P&gt;</description>
    <pubDate>Wed, 19 Mar 2025 22:02:55 GMT</pubDate>
    <dc:creator>BPry</dc:creator>
    <dc:date>2025-03-19T22:02:55Z</dc:date>
    <item>
      <title>IKEV2 w Cert - Wildcard peer for DN does not work.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ikev2-w-cert-wildcard-peer-for-dn-does-not-work/m-p/1224230#M123702</link>
      <description>&lt;P&gt;Can someone please give me the format you are using for the peer id using DN with a wildcard. CN= ??&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I try&amp;nbsp;&lt;/P&gt;
&lt;P&gt;CN=*&lt;/P&gt;
&lt;P&gt;CN=lab-fw-vyos-*&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The DN in the logs coming in from the peer is&lt;/P&gt;
&lt;P&gt;lab-fw-vyos-testsite&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;when I try CN=lab-fw-vyos-testsite it works but I want to terminate all peers on this IKE gateway so I need a wildcard. Any ideas?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Nathan&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Mar 2025 18:18:17 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ikev2-w-cert-wildcard-peer-for-dn-does-not-work/m-p/1224230#M123702</guid>
      <dc:creator>NSutfin</dc:creator>
      <dc:date>2025-03-19T18:18:17Z</dc:date>
    </item>
    <item>
      <title>Re: IKEV2 w Cert - Wildcard peer for DN does not work.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ikev2-w-cert-wildcard-peer-for-dn-does-not-work/m-p/1224243#M123709</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/185085"&gt;@NSutfin&lt;/a&gt;,&lt;/P&gt;
&lt;P&gt;When you're configuring the IKE gateway have you made sure that your peer ID check is set to Wildcard and do you have the certification payload identification mismatch box checked at all? &lt;/P&gt;</description>
      <pubDate>Wed, 19 Mar 2025 22:02:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ikev2-w-cert-wildcard-peer-for-dn-does-not-work/m-p/1224243#M123709</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2025-03-19T22:02:55Z</dc:date>
    </item>
    <item>
      <title>Re: IKEV2 w Cert - Wildcard peer for DN does not work.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ikev2-w-cert-wildcard-peer-for-dn-does-not-work/m-p/1224347#M123730</link>
      <description>&lt;P&gt;yes, both are checked. I'd like to see some examples of the peer id field with a wildcard if anyone is using it successfully.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Mar 2025 17:41:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ikev2-w-cert-wildcard-peer-for-dn-does-not-work/m-p/1224347#M123730</guid>
      <dc:creator>NSutfin</dc:creator>
      <dc:date>2025-03-20T17:41:19Z</dc:date>
    </item>
    <item>
      <title>Re: IKEV2 w Cert - Wildcard peer for DN does not work.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ikev2-w-cert-wildcard-peer-for-dn-does-not-work/m-p/1224800#M123778</link>
      <description>&lt;P&gt;Is wildcard supported on non-fqdn names? Have you tried with fqdn, like *.fw.vyos.com or something like that?&lt;/P&gt;</description>
      <pubDate>Wed, 26 Mar 2025 14:29:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ikev2-w-cert-wildcard-peer-for-dn-does-not-work/m-p/1224800#M123778</guid>
      <dc:creator>rmfalconer</dc:creator>
      <dc:date>2025-03-26T14:29:26Z</dc:date>
    </item>
    <item>
      <title>Re: IKEV2 w Cert - Wildcard peer for DN does not work.</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ikev2-w-cert-wildcard-peer-for-dn-does-not-work/m-p/1226851#M124040</link>
      <description>&lt;P&gt;Yes and yes. I spoke to TAC. They said dynamic peer using pre shared keys was not supported. Its a wonder it is allowed as an option. I can use with cert based authentications but not PSK. Anyone else see this issue?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Apr 2025 17:45:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ikev2-w-cert-wildcard-peer-for-dn-does-not-work/m-p/1226851#M124040</guid>
      <dc:creator>NSutfin</dc:creator>
      <dc:date>2025-04-17T17:45:32Z</dc:date>
    </item>
  </channel>
</rss>

