<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global Protect Portal/Gateway Certificate Issue in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-portal-gateway-certificate-issue/m-p/4723#M3484</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just recently after upgrading to Global Protect Version 1.2.4 we started getting error messages on our external users laptops that there was an " CN Mismatch Name" but continuing still allowed them to connect..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After determing it was a Common Name issue with the Device Certificate " web-server" - Subject "Local Host"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am now after some instructions on how to setup a new certificate with a common name of the IP Address of the Tunnel Interface..&amp;nbsp; and then configure this within the Portal and Gateway sections of the PA 2050..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Creating a new certificate currently doesn't open the Portal Page and when trying to connect with the Global Protect client nothing happens ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any assistance would be great..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks Simon &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 05 Jul 2013 04:09:06 GMT</pubDate>
    <dc:creator>acmi</dc:creator>
    <dc:date>2013-07-05T04:09:06Z</dc:date>
    <item>
      <title>Global Protect Portal/Gateway Certificate Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-portal-gateway-certificate-issue/m-p/4723#M3484</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just recently after upgrading to Global Protect Version 1.2.4 we started getting error messages on our external users laptops that there was an " CN Mismatch Name" but continuing still allowed them to connect..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After determing it was a Common Name issue with the Device Certificate " web-server" - Subject "Local Host"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am now after some instructions on how to setup a new certificate with a common name of the IP Address of the Tunnel Interface..&amp;nbsp; and then configure this within the Portal and Gateway sections of the PA 2050..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Creating a new certificate currently doesn't open the Portal Page and when trying to connect with the Global Protect client nothing happens ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any assistance would be great..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks Simon &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Jul 2013 04:09:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-portal-gateway-certificate-issue/m-p/4723#M3484</guid>
      <dc:creator>acmi</dc:creator>
      <dc:date>2013-07-05T04:09:06Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect Portal/Gateway Certificate Issue</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-portal-gateway-certificate-issue/m-p/4724#M3485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Instructions assuming&lt;/P&gt;&lt;P&gt;a&amp;gt;Using Self signed certificates&lt;/P&gt;&lt;P&gt;b&amp;gt; Firewall acting as Portal and Gateway both.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1&amp;gt;Generate a New CA Certificate (Check the box &lt;SPAN style="color: #222222; font-family: Tahoma, Arial, Helvetica, sans-serif; font-size: 11px; background-color: #ebedee;"&gt;Certificate Authority&lt;/SPAN&gt;) on PANOS firewall [ (Device&amp;gt;Certificates)]&lt;/P&gt;&lt;P&gt;The common name of the certificate must be either the IP address or FQDN of the egress interface of&lt;/P&gt;&lt;P&gt;the firewall where the clients connect.&lt;/P&gt;&lt;P&gt;2&amp;gt;This certificate can be used as a Server Certificate in the Portal and Gateway sections.&lt;/P&gt;&lt;P&gt;3&amp;gt;Also verify if the Gateway IP has been correctly configured Under:&lt;/P&gt;&lt;P&gt;:Network&amp;gt;GlobalProtect &amp;gt; Portals&amp;gt;Client Configuration tab&amp;gt;External Gateways&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For quick instructions for the rest of Config:&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/docs/DOC-2904"&gt;How to Configure GlobalProtect&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For Detailed Instructions :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="2020" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A __default_attr="2568" __jive_macro_name="document" class="jive_macro jive_macro_document" href="https://live.paloaltonetworks.com/"&gt;&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Jul 2013 07:31:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-portal-gateway-certificate-issue/m-p/4724#M3485</guid>
      <dc:creator>UhMayYeah</dc:creator>
      <dc:date>2013-07-05T07:31:05Z</dc:date>
    </item>
  </channel>
</rss>

