<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Active Passive  and Active Active PA  and Web Gui Cert in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/active-passive-and-active-active-pa-and-web-gui-cert/m-p/249487#M70953</link>
    <description>&lt;P&gt;You can't use seperate for passive firewall.&lt;/P&gt;&lt;P&gt;This part of the config is synced it means that same cert is used for both active and passive.&lt;/P&gt;&lt;P&gt;Wildcard is probably best way to go.&lt;/P&gt;</description>
    <pubDate>Fri, 08 Feb 2019 18:30:34 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2019-02-08T18:30:34Z</dc:date>
    <item>
      <title>Active Passive  and Active Active PA  and Web Gui Cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-passive-and-active-active-pa-and-web-gui-cert/m-p/249387#M70921</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have created CSR and exported that to our Server team as they &lt;SPAN&gt;would generate the cert based off of that.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;PA is in active passive mode.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do webgui cert of Active PA will syn with Passive PA?&lt;/P&gt;&lt;P&gt;Do I need to create separte CSR for the passive PA?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We also have PA in Active Active mode.&lt;/P&gt;&lt;P&gt;Does A/P Webgui Cert process is same as Active Active PA?&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 03:47:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-passive-and-active-active-pa-and-web-gui-cert/m-p/249387#M70921</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-02-08T03:47:27Z</dc:date>
    </item>
    <item>
      <title>Re: Active Passive  and Active Active PA  and Web Gui Cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-passive-and-active-active-pa-and-web-gui-cert/m-p/249463#M70943</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Yes you will need a new csr and cert as certificates are not shared during a commit or config sync.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 15:48:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-passive-and-active-active-pa-and-web-gui-cert/m-p/249463#M70943</guid>
      <dc:creator>OtakarKlier</dc:creator>
      <dc:date>2019-02-08T15:48:58Z</dc:date>
    </item>
    <item>
      <title>Re: Active Passive  and Active Active PA  and Web Gui Cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-passive-and-active-active-pa-and-web-gui-cert/m-p/249476#M70947</link>
      <description>&lt;P&gt;Certificates are shared in HA config and also webgui cert config (Device &amp;gt; Setup &amp;gt; Management &amp;gt; Authentication Settings).&lt;/P&gt;&lt;P&gt;So unless you use wildcard you will still get error when you log into one of them as both webgui's have their own DNS name.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Most likely SAN cert that has DNS name of both webgui's on it will work aswell but I have not tested it.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 16:50:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-passive-and-active-active-pa-and-web-gui-cert/m-p/249476#M70947</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-02-08T16:50:32Z</dc:date>
    </item>
    <item>
      <title>Re: Active Passive  and Active Active PA  and Web Gui Cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-passive-and-active-active-pa-and-web-gui-cert/m-p/249480#M70949</link>
      <description>&lt;P&gt;Can you please explain about this in more&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF6600"&gt;&lt;SPAN&gt;So unless you use wildcard you will still get error when you log into one of them as both webgui's have their own DNS name.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Currently on active PA i used the common name as host name of the PA&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 17:20:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-passive-and-active-active-pa-and-web-gui-cert/m-p/249480#M70949</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-02-08T17:20:59Z</dc:date>
    </item>
    <item>
      <title>Re: Active Passive  and Active Active PA  and Web Gui Cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-passive-and-active-active-pa-and-web-gui-cert/m-p/249481#M70950</link>
      <description>&lt;P&gt;Well it does not matter that your firewalls are set into HA.&lt;/P&gt;&lt;P&gt;They both still have their own management IP (unless you manage it through network interface).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let's assume that:&lt;/P&gt;&lt;P&gt;PA1 mgmt IP is 10.0.0.11&lt;/P&gt;&lt;P&gt;PA1 mgmt interface DNS name PA1.corp.local that resolves to&amp;nbsp;&lt;SPAN&gt;10.0.0.11&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PA2 mgmt IP is 10.0.0.12&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;PA2 mgmt interface DNS name PA2.corp.local&amp;nbsp;that resolves to&amp;nbsp;10.0.0.12&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Then you either need *.corp.local cert or SAN cert that has both&amp;nbsp;PA1.corp.local and&amp;nbsp;PA2.corp.local on it.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Management interface cert config is shared between firewalls.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 17:26:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-passive-and-active-active-pa-and-web-gui-cert/m-p/249481#M70950</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-02-08T17:26:59Z</dc:date>
    </item>
    <item>
      <title>Re: Active Passive  and Active Active PA  and Web Gui Cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-passive-and-active-active-pa-and-web-gui-cert/m-p/249484#M70951</link>
      <description>&lt;P&gt;Yes i am using Web Gui cert for the Management interface of both firewalls.&lt;/P&gt;&lt;P&gt;So what I can do now is use this common name on both firewalls while generating the CSR ?&lt;/P&gt;&lt;P&gt;for example&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;*.NGFW&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Then I do not need to create separate CSR for passive device right?&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 17:34:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-passive-and-active-active-pa-and-web-gui-cert/m-p/249484#M70951</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-02-08T17:34:37Z</dc:date>
    </item>
    <item>
      <title>Re: Active Passive  and Active Active PA  and Web Gui Cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-passive-and-active-active-pa-and-web-gui-cert/m-p/249487#M70953</link>
      <description>&lt;P&gt;You can't use seperate for passive firewall.&lt;/P&gt;&lt;P&gt;This part of the config is synced it means that same cert is used for both active and passive.&lt;/P&gt;&lt;P&gt;Wildcard is probably best way to go.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 18:30:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-passive-and-active-active-pa-and-web-gui-cert/m-p/249487#M70953</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2019-02-08T18:30:34Z</dc:date>
    </item>
    <item>
      <title>Re: Active Passive  and Active Active PA  and Web Gui Cert</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/active-passive-and-active-active-pa-and-web-gui-cert/m-p/249525#M70965</link>
      <description>&lt;P&gt;Many Thanks Raido will give it a&amp;nbsp; try.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 22:36:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/active-passive-and-active-active-pa-and-web-gui-cert/m-p/249525#M70965</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-02-08T22:36:40Z</dc:date>
    </item>
  </channel>
</rss>

