<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dual ISP in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34605#M25394</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Even if the url and IP address are different?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 21 Aug 2014 15:40:35 GMT</pubDate>
    <dc:creator>infotech</dc:creator>
    <dc:date>2014-08-21T15:40:35Z</dc:date>
    <item>
      <title>Dual ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34603#M25392</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My main PA is configured for dual ISP's and I am going to put third party certs for my global protect clients. Do I put two certs on? One for each ISP?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Aug 2014 13:51:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34603#M25392</guid>
      <dc:creator>infotech</dc:creator>
      <dc:date>2014-08-21T13:51:00Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34604#M25393</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Infotech,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use the same &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;cert&lt;/SPAN&gt; for both ISP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Aug 2014 14:42:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34604#M25393</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-08-21T14:42:23Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34605#M25394</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Even if the url and IP address are different?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Aug 2014 15:40:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34605#M25394</guid>
      <dc:creator>infotech</dc:creator>
      <dc:date>2014-08-21T15:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34606#M25395</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN class="GINGER_SOFTWARE_mark"&gt;it&lt;/SPAN&gt; might give you a certificate CN mismatch warning.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Aug 2014 15:43:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34606#M25395</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-08-21T15:43:37Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34607#M25396</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can follow the suggestion given by Steven Pulika in the other discussion thread.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Aug 2014 15:56:25 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34607#M25396</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-08-21T15:56:25Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34608#M25397</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;infotech,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Think of a certificate as belonging to a FQDN - you should have one certificate per FQDN. For example, many people create an A record in their external DNS server for vpn.mycompany.com - then purchase a certificate for vpn.mycompany.com. Via DNS, you can modify the IP behind that URL at anytime, but the certificate will always match the URL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have two separate URLs with different FQDNs, you will need two separate certificates. If you have one FQDN but two IP addresses, you only need one certificate.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Aug 2014 14:12:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34608#M25397</guid>
      <dc:creator>jtyler</dc:creator>
      <dc:date>2014-08-22T14:12:12Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34609#M25398</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;So if I use the ip address instead of the FQDM it gives me the cert error but I can go ahead and click continue and it still works right? But if I use the FQDn it doesn't give me an error and passes me on to where I am going. Other than the annoying message how is that batter?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Aug 2014 17:17:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34609#M25398</guid>
      <dc:creator>infotech</dc:creator>
      <dc:date>2014-08-25T17:17:14Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34610#M25399</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Infotech,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes you are right, its just an cert error, and it will still work. There is a logic behind error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If user tries to access Site through IP and cert has FQDN than user gets warning that "He might be connected to wrong site because certificate has different CN(FQDN) name".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Basically software is trying to inform user that he might be connecting to fake site. So, now user has chance to relook URL and certificate details to validate the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Sometimes Hackers change DNS records. Lets say they change DNS record for bankofamerica.com and point it to their server. Now user is connecting to &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://bankofamerica.com" rel="nofollow"&gt;https://bankofamerica.com&lt;/A&gt;&lt;SPAN&gt;, he connects to hackers server. But hackers server gives certificate with different CN name. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now software prompts user to check certificate, based on certificate CN name he can determine its an attack. So its security mechanism.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Aug 2014 17:27:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34610#M25399</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-08-25T17:27:48Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34611#M25400</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well if I am trying to connect through a global protect client does it really matter if the get the error and have to hit continue. It seems like it would be more usefull if they were found not to have the correct cert on them they would be denied access.&lt;/P&gt;&lt;P&gt;Remoting to a network using global protect is different that going to a wrong web site.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Aug 2014 19:29:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34611#M25400</guid>
      <dc:creator>infotech</dc:creator>
      <dc:date>2014-08-25T19:29:59Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34612#M25401</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Infotech,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;GP and accessing website follows same logic as long as certificate is considered.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In your case certificate error doesnt matter, user can still access GP, he just need to accept warning. Let me know if you have further query.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Aug 2014 19:33:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34612#M25401</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-08-25T19:33:32Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34613#M25402</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Infotech,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have an option in GP configuration, if the portal certificate is invalid, the user will not be able to connect to the GP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FYI:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="GP-cert.jpg" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/15069_GP-cert.jpg" style="height: 421px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Aug 2014 19:41:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34613#M25402</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-08-25T19:41:57Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34614#M25403</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Where is the setting located at hulk I don't see it&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Aug 2014 19:45:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34614#M25403</guid>
      <dc:creator>infotech</dc:creator>
      <dc:date>2014-08-25T19:45:34Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34615#M25404</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Go to Network &amp;gt; Global Protect &amp;gt; Portal &amp;gt;Agent configuration. There you will get these options.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Aug 2014 19:48:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34615#M25404</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-08-25T19:48:06Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34616#M25405</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I went there and I don't see it&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Aug 2014 19:49:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34616#M25405</guid>
      <dc:creator>infotech</dc:creator>
      <dc:date>2014-08-25T19:49:11Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34617#M25406</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you please share a screenshot.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Aug 2014 19:56:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34617#M25406</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-08-25T19:56:09Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34618#M25407</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;what are you referring too when you say external DNS server?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Aug 2014 20:30:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34618#M25407</guid>
      <dc:creator>infotech</dc:creator>
      <dc:date>2014-08-25T20:30:34Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34619#M25408</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Could you please login as admin user and verify this option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Aug 2014 20:30:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34619#M25408</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-08-25T20:30:54Z</dc:date>
    </item>
    <item>
      <title>Re: Dual ISP</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34620#M25409</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Same options when I log in as an admin and my PA version is 5.06&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Aug 2014 20:54:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/dual-isp/m-p/34620#M25409</guid>
      <dc:creator>infotech</dc:creator>
      <dc:date>2014-08-25T20:54:31Z</dc:date>
    </item>
  </channel>
</rss>

