<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Configuring GlobalProtect with Wildcard Certificate in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/configuring-globalprotect-with-wildcard-certificate/m-p/70627#M40561</link>
    <description>&lt;P&gt;1&amp;gt; If you are using a public certificate then yes. "&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Generate-a-CSR-Certificate-Signing-Request-and-Import-the/ta-p/53593&amp;quot;" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Generate-a-CSR-Certificate-Signing-Request-and-Import-the/ta-p/53593&lt;/A&gt;"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2&amp;gt; You have to have a entry in external dns server for mapping of vpn.example.com to the interface IP address.&lt;/P&gt;</description>
    <pubDate>Tue, 28 Apr 2020 14:26:44 GMT</pubDate>
    <dc:creator>pankaku</dc:creator>
    <dc:date>2020-04-28T14:26:44Z</dc:date>
    <item>
      <title>Configuring GlobalProtect with Wildcard Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuring-globalprotect-with-wildcard-certificate/m-p/70585#M40552</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;I'm configuring GlobalProtect for the first time and would like to ask a few questions about using a &lt;STRONG&gt;Wildcard certificate&lt;/STRONG&gt; to set this up. After going through the below document, I have some questions:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Use-a-Wildcard-SSL-Certificate-with-Subject-Alternative/ta-p/52849" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/How-to-Use-a-Wildcard-SSL-Certificate-with-Subject-Alternative/ta-p/52849&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1. The first steps says a Root CA should be created.Does this mean setting the 'Common name' as the wildcard domain name, 'Signed by' External Authority CSR and still ticking the '&lt;STRONG&gt;Certificate Authority&lt;/STRONG&gt;' checkbox (e.g image attached)?&lt;IMG src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/1973i4D6D63D0B3E6719C/image-size/medium?v=mpbl-1&amp;amp;px=-1" border="0" alt="gp1.png" title="gp1.png" /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. I would like the users to access Globalprotect using the address 'vpn.example.com'. If I configure this under the Certificate attributes, will this automatically map it to the Interface IP address I choose for my Gateway IP address?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Your contributions are appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jan 2016 16:37:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuring-globalprotect-with-wildcard-certificate/m-p/70585#M40552</guid>
      <dc:creator>Bocsa</dc:creator>
      <dc:date>2016-01-08T16:37:12Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring GlobalProtect with Wildcard Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuring-globalprotect-with-wildcard-certificate/m-p/70627#M40561</link>
      <description>&lt;P&gt;1&amp;gt; If you are using a public certificate then yes. "&lt;A href="https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Generate-a-CSR-Certificate-Signing-Request-and-Import-the/ta-p/53593&amp;quot;" target="_blank" rel="noopener"&gt;https://live.paloaltonetworks.com/t5/Configuration-Articles/How-to-Generate-a-CSR-Certificate-Signing-Request-and-Import-the/ta-p/53593&lt;/A&gt;"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2&amp;gt; You have to have a entry in external dns server for mapping of vpn.example.com to the interface IP address.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2020 14:26:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuring-globalprotect-with-wildcard-certificate/m-p/70627#M40561</guid>
      <dc:creator>pankaku</dc:creator>
      <dc:date>2020-04-28T14:26:44Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring GlobalProtect with Wildcard Certificate</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/configuring-globalprotect-with-wildcard-certificate/m-p/70651#M40569</link>
      <description>&lt;P&gt;1. If you are using PA as the Certificate Authority (i.e using self signed certificate), then generate the Root certificate on the firewall (Signed by Field as Blank and Certificate Authority check box ticked). If you are using external CA, then Root CA certificate just needs to be imported on the firewall. In this step, you do NOT need any wildcards.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Only when you are generating certificates for portal or gateway, you have to use the wildcard in the common name (Step 2)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;2. Certificate attributes will not map anything. They are static field in the certificate. If you want users to resolve vpn.example.com to your Interface IP address, that should be recorded on the DNS server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2016 02:25:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/configuring-globalprotect-with-wildcard-certificate/m-p/70651#M40569</guid>
      <dc:creator>abjain</dc:creator>
      <dc:date>2016-01-11T02:25:35Z</dc:date>
    </item>
  </channel>
</rss>

