<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Global protect certificate in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31912#M23367</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;
&lt;P&gt;infotech wrote:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So does the 3rd party cert with a FQDN that I create with generating the CSR end up being the external DNS name out in cyber space? I don't see that is would be something I would create and put on the internal dns server.&lt;/P&gt;
&lt;/PRE&gt;&lt;P&gt;Whether or not you need the DNS entry on your internet facing DNS depends on where your users access the service from.&amp;nbsp; With global protect remote access you will likely need that record setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the users are purely employees, you could deploy that record as a hosts file on the company computers via group policy if you don't want a DNS record out there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've never done so, but I suppose you could submit the ip address as the FQDN for the certificate.&amp;nbsp; If so, that would pass the first of the three tests run for validity.&amp;nbsp; The name entered into the connection must match the FQDN on the certificate otherwise a certificate error will be triggered.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 30 Aug 2014 13:21:56 GMT</pubDate>
    <dc:creator>pulukas</dc:creator>
    <dc:date>2014-08-30T13:21:56Z</dc:date>
    <item>
      <title>Global protect certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31878#M23333</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;What are the steps to apply a 3rd party certificate to a global protect client instead of using a self signed cert?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Aug 2014 15:05:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31878#M23333</guid>
      <dc:creator>infotech</dc:creator>
      <dc:date>2014-08-11T15:05:05Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31879#M23334</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Import both your public cert authority and your certificate CA in your palo.&lt;/P&gt;&lt;P&gt;Then use your CA in authent profile.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Aug 2014 15:15:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31879#M23334</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2014-08-11T15:15:54Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31880#M23335</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Refer to: &lt;A href="https://live.paloaltonetworks.com/docs/DOC-6586"&gt;GlobalProtect Administrator's Guide 6.0 (English)&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;V.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Aug 2014 15:18:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31880#M23335</guid>
      <dc:creator>VinceM</dc:creator>
      <dc:date>2014-08-11T15:18:11Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31881#M23336</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I will check this out&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Aug 2014 15:24:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31881#M23336</guid>
      <dc:creator>infotech</dc:creator>
      <dc:date>2014-08-11T15:24:23Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31882#M23337</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;By public you mean a cert purchased by a 3rd party and I don't believe we have a CA server&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Aug 2014 15:34:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31882#M23337</guid>
      <dc:creator>infotech</dc:creator>
      <dc:date>2014-08-11T15:34:20Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31883#M23338</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Few more reference DOC:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-1937"&gt;PAN SSL Certificates&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-4923"&gt;Global_Protect_PAN_OS5.pdf&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Aug 2014 15:43:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31883#M23338</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-08-11T15:43:02Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31884#M23339</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good information thanks. We currently have a self signed cert for our global protect and I want to change it to a third party. I assume it only has to be imported to the PA device and does not have to be on a pc that has the GP client installed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Aug 2014 15:50:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31884#M23339</guid>
      <dc:creator>infotech</dc:creator>
      <dc:date>2014-08-11T15:50:00Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31885#M23340</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, that is correct. During the SSL handshake, PAN will push the certificate information to the client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-2020"&gt;GlobalProtect&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Aug 2014 15:53:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31885#M23340</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-08-11T15:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31886#M23341</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is what is currently configured&lt;IMG alt="gpcert.png" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14888_gpcert.png" style="width: 620px; height: 477px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Aug 2014 15:56:07 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31886#M23341</guid>
      <dc:creator>infotech</dc:creator>
      <dc:date>2014-08-11T15:56:07Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31887#M23342</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Infotech&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will; be probablyh faced with intermediary cert problem, so here You are solution:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-4289"&gt;How to Install a Chained Certificate Signed by a Public CA&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;SLawek&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Aug 2014 18:31:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31887#M23342</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-08-11T18:31:35Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31888#M23343</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This looks like instrucations on how to install it on a server&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Aug 2014 18:39:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31888#M23343</guid>
      <dc:creator>infotech</dc:creator>
      <dc:date>2014-08-11T18:39:14Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31889#M23344</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;yes, PAN is a server for GP, please follow &lt;A href="https://live.paloaltonetworks.com/docs/DOC-6021"&gt;Importing Chained PEM Format Certificates - Using Text Editor&lt;/A&gt; and import Your cert into PAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can verify is that properly configured using &lt;A href="http://www.sslshopper.com/ssl-checker.html#hostname=your.gp.site.com" title="http://www.sslshopper.com/ssl-checker.html#hostname=your.gp.site.com"&gt;SSL Checker - SSL Certificate Verify&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Slaweke&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Aug 2014 19:02:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31889#M23344</guid>
      <dc:creator>_slv_</dc:creator>
      <dc:date>2014-08-11T19:02:26Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31890#M23345</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So you have to do like for any server that has a cert on it export the existing key, send it to a 3rd party vendor,get anothe key and import it onto the PA&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Aug 2014 19:04:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31890#M23345</guid>
      <dc:creator>infotech</dc:creator>
      <dc:date>2014-08-11T19:04:59Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31891#M23346</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think this link I found inside one of the responses is what I really need&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-4232"&gt;How to Generate a CSR(Certificate Signing Request) and Import the Signed Certificate&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Aug 2014 19:15:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31891#M23346</guid>
      <dc:creator>infotech</dc:creator>
      <dc:date>2014-08-11T19:15:01Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31892#M23347</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What do you put that FQDN?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Aug 2014 19:19:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31892#M23347</guid>
      <dc:creator>infotech</dc:creator>
      <dc:date>2014-08-11T19:19:53Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31893#M23348</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What I meant to say in my last comment is what do you enter for the FQDM since that PA is not a server. It was pointed out to use during a security audit that we were using a self signed certs and one of my tasks is to put a more secure 3rd party cert on the global protect clients. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Aug 2014 19:57:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31893#M23348</guid>
      <dc:creator>infotech</dc:creator>
      <dc:date>2014-08-11T19:57:56Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31894#M23349</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It should be a domain name, which will resolve to PAN public IP address (portal address). You can specify the IP address of that interface also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Aug 2014 20:09:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31894#M23349</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-08-11T20:09:04Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31895#M23350</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;BR /&gt;Well I don't have any records in DNS for the PA and it has more than one ISP address&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Aug 2014 20:11:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31895#M23350</guid>
      <dc:creator>infotech</dc:creator>
      <dc:date>2014-08-11T20:11:43Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31896#M23351</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You may specify the GP-portal IP address.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Aug 2014 20:13:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31896#M23351</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-08-11T20:13:15Z</dc:date>
    </item>
    <item>
      <title>Re: Global protect certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31897#M23352</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So would it be the 66.94.208.114 address indicated in the pic that I have uploaded with this message and also what if I have a secondary ISP that I fail over too. Will global protect still work? Do I need another cert for that secondary ISP address?&lt;IMG alt="gpportal.bmp" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14889_gpportal.bmp" style="width: 620px; height: 477px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Aug 2014 21:03:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-certificate/m-p/31897#M23352</guid>
      <dc:creator>infotech</dc:creator>
      <dc:date>2014-08-11T21:03:30Z</dc:date>
    </item>
  </channel>
</rss>

