accessing Panorma GUI in eve-ng lab environment, certificate issues with chrome

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements
Please sign in to see details of an important advisory in our Customer Advisories area.

accessing Panorma GUI in eve-ng lab environment, certificate issues with chrome

L2 Linker

So i've set up some firewall images in eve-ng 10.0.4,

 

I dhcp'd the management interfaces, connectivity is fine everything working as expected, 

except I can't access the GUI on my local host chrome browser

FortiNSE1.png

 

 

Giving me the error:

NET::ERR_CERT_COMMON_NAME_INVALID

 

so I can't access the GUI, and I read on some other post about changing the alternative name as potentially solving the issue:  https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000CluVCAS

among other Live forum discussions.

 

And so i can't do that in the GUI, so i figured I would try CLI,

 

 

FortiNSE1.png

 

I tried adding a random name with the ip as the FQDN, as one of the LIVE posts this may fix the issue just to give it a try and I get the failed to insert error.

 

Can someone guide me on how to fix my problem?

 

5 REPLIES 5

L2 Linker

Oh yeah and this,

FortiNSE1.png

 

 

So I'm thinking I need to actually set up some type of cert first which is the real issue at hand. How to do that via CLI?

 

L2 Linker

And I'm getting syntax errors when trying to generate a cert...

 

FortiNSE1.png

 

 

L2 Linker

So so i managed to set up the cert on the PA device with this CLI command:

 

equest certificate generate ca yes digest sha256 algorithm RSA rsa-nbits 2048 certificate-name PA9 name 192.168.56.136

 

however when trying to get to the GUI via web browser  I get this error:

 

NET::ERR_CERT_COMMON_NAME_INVALID

 

 

so if anyone could guide me on this it would be awesome

 

L2 Linker

I got it working just by typing http  instead of https

 

XD

 

FortiNSE1.png

 

I'm going to be posting some heavy scripting soon, and maybe rolling it up into a bigger program to post on my github, so if you're interested would like to follow along and to help me you can check out my upcoming posts and follow my github 🙂

Cyber Elite
Cyber Elite

Hi @hfakoor2 ,

 

Did you use an SSL/TLS Service Profile to attach the certificate to the web UI (Panorama > Setup > Management > General Settings > SSL/TLS Service Profile)?

 

Thanks,

 

Tom

Help the community: Like helpful comments and mark solutions.
  • 1202 Views
  • 5 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!