<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Rename CN name certificate GlobalProtect . in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/rename-cn-name-certificate-globalprotect/m-p/329303#M83614</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have question, currently, on firewall PA-500, we do 2 gateway VPN. Its mean have 2 WAN(ISP).&amp;nbsp; So few users will use VPN via WAN1, and few users will use VPN via WAN2.&amp;nbsp; Existing VPN using WAN1. So certificate CN name(IP address) point to Gateway WAN1.&amp;nbsp; after added WAN2 and new gateway from WAN2. We notice have certificate mismatch when users try to connect GP VPN IP gateway WAN2.&lt;BR /&gt;&lt;BR /&gt;So if I rename CN name of certificate from IP ADDRESS TO FQDN, have any charge from Palo Alto.? Or free to rename. not need to pay.?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Fri, 22 May 2020 03:12:16 GMT</pubDate>
    <dc:creator>abdulhakam</dc:creator>
    <dc:date>2020-05-22T03:12:16Z</dc:date>
    <item>
      <title>Rename CN name certificate GlobalProtect .</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rename-cn-name-certificate-globalprotect/m-p/329303#M83614</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have question, currently, on firewall PA-500, we do 2 gateway VPN. Its mean have 2 WAN(ISP).&amp;nbsp; So few users will use VPN via WAN1, and few users will use VPN via WAN2.&amp;nbsp; Existing VPN using WAN1. So certificate CN name(IP address) point to Gateway WAN1.&amp;nbsp; after added WAN2 and new gateway from WAN2. We notice have certificate mismatch when users try to connect GP VPN IP gateway WAN2.&lt;BR /&gt;&lt;BR /&gt;So if I rename CN name of certificate from IP ADDRESS TO FQDN, have any charge from Palo Alto.? Or free to rename. not need to pay.?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2020 03:12:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rename-cn-name-certificate-globalprotect/m-p/329303#M83614</guid>
      <dc:creator>abdulhakam</dc:creator>
      <dc:date>2020-05-22T03:12:16Z</dc:date>
    </item>
    <item>
      <title>Re: Rename CN name certificate GlobalProtect .</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rename-cn-name-certificate-globalprotect/m-p/329312#M83615</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/134123"&gt;@abdulhakam&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It seems you are using Palo Alto self signed certificate for your GP VPN. For VPN 2, you can generate new certificate and use it in new ssl profile. This profile can be used for VPN2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If you are trying to change CN of existing self signed certificate, may be system won't allow you to change it. Best way is to generate new cert and use it for VPN2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There shouldn't be any cost or charges involved in this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope it helps!&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Fri, 22 May 2020 05:49:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rename-cn-name-certificate-globalprotect/m-p/329312#M83615</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-05-22T05:49:41Z</dc:date>
    </item>
    <item>
      <title>Re: Rename CN name certificate GlobalProtect .</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rename-cn-name-certificate-globalprotect/m-p/329816#M83687</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521"&gt;@SutareMayur&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks For Answer,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, I can't rename the CN existing. I will generate new certificate and CN name will be FQDN not IP Address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It will work if i have using two gateway(VPN1 and VPN2) using CN name FQDN.?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2020 07:13:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rename-cn-name-certificate-globalprotect/m-p/329816#M83687</guid>
      <dc:creator>abdulhakam</dc:creator>
      <dc:date>2020-05-26T07:13:23Z</dc:date>
    </item>
    <item>
      <title>Re: Rename CN name certificate GlobalProtect .</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rename-cn-name-certificate-globalprotect/m-p/329832#M83688</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/134123"&gt;@abdulhakam&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes it will work using certificate which is generated for FQDN as well. If you are using FQDN to connect GP then that certificate will get accepted and trust will be build. If you are using IP address to connect GP and certificate used is generated for CN as FQDN then there will be mismatch. So you need to check in this regard also.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Tue, 26 May 2020 07:55:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rename-cn-name-certificate-globalprotect/m-p/329832#M83688</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-05-26T07:55:08Z</dc:date>
    </item>
    <item>
      <title>Re: Rename CN name certificate GlobalProtect .</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rename-cn-name-certificate-globalprotect/m-p/332238#M84016</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/132521"&gt;@SutareMayur&lt;/a&gt;&amp;nbsp; ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Best way is to generate new cert and use it for VPN2."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;U mean generate new cert and setup same like existing cert. I mean setup From A to Z..&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;like this &lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFoCAK" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClFoCAK&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jun 2020 08:21:27 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rename-cn-name-certificate-globalprotect/m-p/332238#M84016</guid>
      <dc:creator>abdulhakam</dc:creator>
      <dc:date>2020-06-08T08:21:27Z</dc:date>
    </item>
    <item>
      <title>Re: Rename CN name certificate GlobalProtect .</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/rename-cn-name-certificate-globalprotect/m-p/332483#M84054</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/134123"&gt;@abdulhakam&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, you can generate new certificate on Palo Alto. Then create new SSL/TLS profile and map that certificate in it. You can use this SSL/TLS profile for VPN2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Mayur&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jun 2020 04:47:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/rename-cn-name-certificate-globalprotect/m-p/332483#M84054</guid>
      <dc:creator>SutareMayur</dc:creator>
      <dc:date>2020-06-09T04:47:34Z</dc:date>
    </item>
  </channel>
</rss>

