- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
02-20-2024 01:22 AM
Hello.
so in regards to the palo advisory of upgrading and rolling out device certificates we are running into an issue which I'm not sure what the impact is.
we have a number of panorama managed firewall clusters. however these firewalls don't use their mgmt/oob interface for connections to palo alto services or dns.
as a result after following the OTP procedure for a palo alto managed firewall the active node of the cluster gets a valid certificate without issue. the passive node remains at none.
we ca make the passive node active briefly so that it can retrieve a certificate whilst active however this certificate expires after 90 days, will try to renew after 75 days by default. if the node is passive this will fail.
It's unclear to me what the impac tof this is. will a (passive) firewall with an expired device certificate still be able to renew as soon as it becomes active without issue?
will a firewall with an expired certificate run into any issues being connected to log collectors or panorama?
I doubt we are the only people with a setup where either dns or palo alto update services are not sent out using the dedicated mgmt interface or where the dedicated mgmt interface is not allowed to go to the internet.
can anyone clarify here what the impact is and ithere is what workarounds there can be?
02-20-2024 12:10 PM
Hi @TommieVanHove ,
I've referred your question to the customer advisory team. Thanks for your patience!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!