<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Trying to configure GlobalProtect VPN with user certificates on 4.1.x in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/trying-to-configure-globalprotect-vpn-with-user-certificates-on/m-p/35350#M25968</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I currently have a PA-500 running 4.1.2 and am trying to configure a client certificate-based VPN as outlined in this document:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;A __default_attr="1991" __jive_macro_name="document" class="jive_macro jive_macro_document default_title"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, that document is for the old NetConnect (pre-4.1.x) VPNs so I've been trying to merge the instructions contained therein with the the 4.1.x GlobalProtect instructions:&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="1999" __jive_macro_name="document" class="jive_macro jive_macro_document default_title"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been able to get the appropriate certificates installed on user machines and uploaded to the firewall.&amp;nbsp; At this point, however, I'm unsure on how to proceed--when configuring the portal where do I use the firewall-supplied CA/certificates and where do I use the server-supplied CA/certificates?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Furthermore, I'm pretty green on the whole certificates and VPN thing.&amp;nbsp; I've used both and have some understanding of them, but this is my first time implementing a VPN (on a Palo Alto device or otherwise).&amp;nbsp; Does anybody know of some sort of "VPN basics" guide here on the Palo Alto site that will assist someone with his first PA VPN setup?&amp;nbsp; I've found plenty of technical guides but most of these assume some familiarity with the subject that I apparently lack.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any help you can provide.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 27 Jan 2012 14:44:56 GMT</pubDate>
    <dc:creator>NinthShot</dc:creator>
    <dc:date>2012-01-27T14:44:56Z</dc:date>
    <item>
      <title>Trying to configure GlobalProtect VPN with user certificates on 4.1.x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trying-to-configure-globalprotect-vpn-with-user-certificates-on/m-p/35350#M25968</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I currently have a PA-500 running 4.1.2 and am trying to configure a client certificate-based VPN as outlined in this document:&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;A __default_attr="1991" __jive_macro_name="document" class="jive_macro jive_macro_document default_title"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, that document is for the old NetConnect (pre-4.1.x) VPNs so I've been trying to merge the instructions contained therein with the the 4.1.x GlobalProtect instructions:&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="1999" __jive_macro_name="document" class="jive_macro jive_macro_document default_title"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have been able to get the appropriate certificates installed on user machines and uploaded to the firewall.&amp;nbsp; At this point, however, I'm unsure on how to proceed--when configuring the portal where do I use the firewall-supplied CA/certificates and where do I use the server-supplied CA/certificates?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Furthermore, I'm pretty green on the whole certificates and VPN thing.&amp;nbsp; I've used both and have some understanding of them, but this is my first time implementing a VPN (on a Palo Alto device or otherwise).&amp;nbsp; Does anybody know of some sort of "VPN basics" guide here on the Palo Alto site that will assist someone with his first PA VPN setup?&amp;nbsp; I've found plenty of technical guides but most of these assume some familiarity with the subject that I apparently lack.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for any help you can provide.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Jan 2012 14:44:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trying-to-configure-globalprotect-vpn-with-user-certificates-on/m-p/35350#M25968</guid>
      <dc:creator>NinthShot</dc:creator>
      <dc:date>2012-01-27T14:44:56Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to configure GlobalProtect VPN with user certificates on 4.1.x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trying-to-configure-globalprotect-vpn-with-user-certificates-on/m-p/35351#M25969</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would suggest starting with this document:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configuring Global Protect&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="2020" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And then as far as Certificates, you should be able to create a local CA, and then create User Certs from there.&lt;/P&gt;&lt;P&gt;Please let us know if you require more information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Jan 2012 21:48:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trying-to-configure-globalprotect-vpn-with-user-certificates-on/m-p/35351#M25969</guid>
      <dc:creator>jdelio</dc:creator>
      <dc:date>2012-01-27T21:48:37Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to configure GlobalProtect VPN with user certificates on 4.1.x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trying-to-configure-globalprotect-vpn-with-user-certificates-on/m-p/35352#M25970</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your reply.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've gotten as far as establishing the local CA and creating user certificates; where I'm getting hung up is where I apply those certificates vs. the certificates self-issued by the firewall (the ones that, to my understanding, are used to establish the link between the firewall and the VPN client).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks again.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 28 Jan 2012 00:28:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trying-to-configure-globalprotect-vpn-with-user-certificates-on/m-p/35352#M25970</guid>
      <dc:creator>NinthShot</dc:creator>
      <dc:date>2012-01-28T00:28:32Z</dc:date>
    </item>
    <item>
      <title>Re: Trying to configure GlobalProtect VPN with user certificates on 4.1.x</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/trying-to-configure-globalprotect-vpn-with-user-certificates-on/m-p/35353#M25971</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It sounds like you are past where that quick start document would be anyway as it describes setting up Global Protect and doesn't describe what to do with the client cert for authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I haven't been able to try yet as I have to go build a CA (and it would appear an external CA is required for client cert auth), but perhaps if you already have one you can give what is described at the bottom of thread 7126 (&lt;/SPAN&gt;&lt;A href="https://live.paloaltonetworks.com/message/7126"&gt;https://live.paloaltonetworks.com/message/7126&lt;/A&gt;&lt;SPAN&gt;) a shot?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jan 2012 20:55:11 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/trying-to-configure-globalprotect-vpn-with-user-certificates-on/m-p/35353#M25971</guid>
      <dc:creator>david3</dc:creator>
      <dc:date>2012-01-30T20:55:11Z</dc:date>
    </item>
  </channel>
</rss>

