<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Global Protect presents wrong TLS certificate of another portal in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-presents-wrong-tls-certificate-of-another-portal/m-p/302642#M78858</link>
    <description>&lt;P&gt;I have a GP portal with TLS/SSL profile named "aaa.ssl.pr" which contains the "aaa-cert" which commons name is "aaa.com"&lt;/P&gt;&lt;P&gt;When accessing the portal I see a different certificate in my web browser,&lt;/P&gt;&lt;P&gt;If I put the same SSL profile on another test portal, I see the correct certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Dec 2019 12:59:43 GMT</pubDate>
    <dc:creator>Trustnet-ET</dc:creator>
    <dc:date>2019-12-09T12:59:43Z</dc:date>
    <item>
      <title>Global Protect presents wrong TLS certificate of another portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-presents-wrong-tls-certificate-of-another-portal/m-p/302642#M78858</link>
      <description>&lt;P&gt;I have a GP portal with TLS/SSL profile named "aaa.ssl.pr" which contains the "aaa-cert" which commons name is "aaa.com"&lt;/P&gt;&lt;P&gt;When accessing the portal I see a different certificate in my web browser,&lt;/P&gt;&lt;P&gt;If I put the same SSL profile on another test portal, I see the correct certificate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2019 12:59:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-presents-wrong-tls-certificate-of-another-portal/m-p/302642#M78858</guid>
      <dc:creator>Trustnet-ET</dc:creator>
      <dc:date>2019-12-09T12:59:43Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect presents wrong TLS certificate of another portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-presents-wrong-tls-certificate-of-another-portal/m-p/302681#M78861</link>
      <description>&lt;P&gt;How very odd....&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the wrong certificate that you are seeing.... Is it one that's on the firewall. or have you no idea where it came from.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2019 14:14:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-presents-wrong-tls-certificate-of-another-portal/m-p/302681#M78861</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-12-09T14:14:05Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect presents wrong TLS certificate of another portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-presents-wrong-tls-certificate-of-another-portal/m-p/302685#M78863</link>
      <description>&lt;P&gt;It is from another test GP portal I have on the same firewall&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2019 14:46:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-presents-wrong-tls-certificate-of-another-portal/m-p/302685#M78863</guid>
      <dc:creator>Trustnet-ET</dc:creator>
      <dc:date>2019-12-09T14:46:32Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect presents wrong TLS certificate of another portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-presents-wrong-tls-certificate-of-another-portal/m-p/302686#M78864</link>
      <description>&lt;P&gt;so when you ping aaa.com, is it a different address to bbb.com&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2019 14:54:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-presents-wrong-tls-certificate-of-another-portal/m-p/302686#M78864</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-12-09T14:54:41Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect presents wrong TLS certificate of another portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-presents-wrong-tls-certificate-of-another-portal/m-p/302690#M78866</link>
      <description>&lt;P&gt;Yes&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2019 15:26:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-presents-wrong-tls-certificate-of-another-portal/m-p/302690#M78866</guid>
      <dc:creator>Trustnet-ET</dc:creator>
      <dc:date>2019-12-09T15:26:10Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect presents wrong TLS certificate of another portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-presents-wrong-tls-certificate-of-another-portal/m-p/302692#M78867</link>
      <description>&lt;P&gt;If you have another GP gateway with no IP configured, it will take precedence and you will see it's certificate when accessing all other gateways which has IP's.&lt;/P&gt;&lt;P&gt;You can change the no IP gateway to a loopback with a dummy IP and the issue will be resolved.&lt;/P&gt;&lt;P&gt;The portal /gateway with no IP address takes priority over the portal configured with an IP address.&lt;/P&gt;&lt;P&gt;Ideally the GP config without an IP is supposed to be done only with DHCP IP and not static IP. So the config using IP as none is incorrect in case of static IP.&lt;/P&gt;&lt;P&gt;I think Palo has to alert when this configuration taking place,&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHRCA0" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClHRCA0&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;TLS Certificate of Global Protect portal /gw with no IP address overrides portal with an IP address&lt;BR /&gt;Global Protect presents wrong TLS certificate of another portal.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2019 15:36:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-presents-wrong-tls-certificate-of-another-portal/m-p/302692#M78867</guid>
      <dc:creator>emilta</dc:creator>
      <dc:date>2019-12-09T15:36:04Z</dc:date>
    </item>
    <item>
      <title>Re: Global Protect presents wrong TLS certificate of another portal</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/global-protect-presents-wrong-tls-certificate-of-another-portal/m-p/302693#M78868</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/83048"&gt;@emilta&lt;/a&gt;&amp;nbsp;, great info... i was not aware of this, probably because all my portals and gateways are static.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have read the link provided but cannot see where it mentions certificate priority, could you forward a link with this info...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Many thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Dec 2019 15:40:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/global-protect-presents-wrong-tls-certificate-of-another-portal/m-p/302693#M78868</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-12-09T15:40:51Z</dc:date>
    </item>
  </channel>
</rss>

