<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Override url ocsp and responder ocsp global protect VPN in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/override-url-ocsp-and-responder-ocsp-global-protect-vpn/m-p/1257712#M126675</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/280315"&gt;@HAINVH&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;What have you tried so far?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;You should be able to host OCSP on an alternate interface instead of tying it to the management IP.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;A few things I would be mindful of:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL data-spread="false"&gt;
&lt;LI&gt;&lt;SPAN&gt;The interface should have an Interface Management Profile applied with &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;HTTP OCSP&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; enabled.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;The OCSP responder hostname/IP should resolve to the data-plane or loopback interface.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Routing and security policy need to allow the OCSP traffic.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 30 Jun 2026 01:18:10 GMT</pubDate>
    <dc:creator>JayGolf</dc:creator>
    <dc:date>2026-06-30T01:18:10Z</dc:date>
    <item>
      <title>Override url ocsp and responder ocsp global protect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/override-url-ocsp-and-responder-ocsp-global-protect-vpn/m-p/1257667#M126674</link>
      <description>&lt;P&gt;Hi everyone,&lt;/P&gt;
&lt;P&gt;present, i have VPN global protec&lt;/P&gt;
&lt;P&gt;Authentication two factor with certificate and radius, by interface management&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The current setup is as follows:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;The Palo Alto firewall acts as both the gateway and the OCSP responder.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;The OCSP responder is configured to use the management IP address, and the OCSP Override URL also points to the management IP.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;SPAN&gt;Because certificate validation relies on the management IP, a failover to the HA peer causes certificate validation to fail. In addition, having only a single management link creates a potential single point of failure.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;To improve resiliency, I would like to use either a data-plane IP address or a loopback IP address as the OCSP responder, and configure the OCSP Override URL to point to that loopback or data-plane IP instead.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;However, I’ve tried several configurations without success.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Could you please help me understand how to achieve this?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;with 1000user i dont want create new all&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jun 2026 14:56:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/override-url-ocsp-and-responder-ocsp-global-protect-vpn/m-p/1257667#M126674</guid>
      <dc:creator>HAINVH</dc:creator>
      <dc:date>2026-06-29T14:56:38Z</dc:date>
    </item>
    <item>
      <title>Re: Override url ocsp and responder ocsp global protect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/override-url-ocsp-and-responder-ocsp-global-protect-vpn/m-p/1257712#M126675</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/280315"&gt;@HAINVH&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;What have you tried so far?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;You should be able to host OCSP on an alternate interface instead of tying it to the management IP.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;A few things I would be mindful of:&lt;/SPAN&gt;&lt;/P&gt;
&lt;UL data-spread="false"&gt;
&lt;LI&gt;&lt;SPAN&gt;The interface should have an Interface Management Profile applied with &lt;/SPAN&gt;&lt;STRONG&gt;&lt;SPAN&gt;HTTP OCSP&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN&gt; enabled.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;The OCSP responder hostname/IP should resolve to the data-plane or loopback interface.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;Routing and security policy need to allow the OCSP traffic.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2026 01:18:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/override-url-ocsp-and-responder-ocsp-global-protect-vpn/m-p/1257712#M126675</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2026-06-30T01:18:10Z</dc:date>
    </item>
    <item>
      <title>Re: Override url ocsp and responder ocsp global protect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/override-url-ocsp-and-responder-ocsp-global-protect-vpn/m-p/1257726#M126676</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="HAINVH_0-1782791520338.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/71903i89837AB793E7A24E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="HAINVH_0-1782791520338.png" alt="HAINVH_0-1782791520338.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I have already created an Interface Management Profile with &lt;STRONG&gt;HTTP&lt;/STRONG&gt; and &lt;STRONG&gt;OCSP&lt;/STRONG&gt; enabled and applied it to the loopback interface, but it still doesn't work.&lt;/P&gt;&lt;P&gt;I have another question. When the Palo Alto device acts as both the gateway and the OCSP responder, do I need to configure any additional routing or security policies for this to work?&lt;/P&gt;&lt;P&gt;Or are you referring to configuring a &lt;STRONG&gt;Service Route&lt;/STRONG&gt; instead?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2026 03:51:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/override-url-ocsp-and-responder-ocsp-global-protect-vpn/m-p/1257726#M126676</guid>
      <dc:creator>HAINVH</dc:creator>
      <dc:date>2026-06-30T03:51:09Z</dc:date>
    </item>
    <item>
      <title>Re: Override url ocsp and responder ocsp global protect VPN</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/override-url-ocsp-and-responder-ocsp-global-protect-vpn/m-p/1257808#M126677</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/280315"&gt;@HAINVH&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;Gotcha, thanks for the info.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;You’ll want to make sure DNS, routing, and security policy are in place so your GlobalProtect clients can resolve and reach the OCSP URL on the loopback address to check certificate status.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;The flow should look something like this:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;GP client resolves the OCSP hostname to the loopback IP → traffic comes from the GP zone → traffic is allowed to the OCSP/Loopback zone&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;For example:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;GP Users → GP Zone → OCSP/Loopback Zone&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jun 2026 13:41:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/override-url-ocsp-and-responder-ocsp-global-protect-vpn/m-p/1257808#M126677</guid>
      <dc:creator>JayGolf</dc:creator>
      <dc:date>2026-06-30T13:41:44Z</dc:date>
    </item>
  </channel>
</rss>

