SSL Certificate update while GP migration

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

SSL Certificate update while GP migration

L2 Linker

Hello,

have scheduled all activities for my FW migration from ASA to PA, however have question about GP migration.

The PA FW has its GP deployed with Public IP x.x.x.6 and gp.domain.com, whereas the ASA has Anyconnect on Public IP x.x.x.5 with asa.domain.com. Both are currently connected to the same ISP; 

 

have disabled Anyconnect, and people have been started using GP which is with public IP address x.x.x.6 and DNS gp.domain.com.

 

Now that we plan to totally shut down ASA and assign the Public IP of ASA to PA during the cutover, the subsequent steps are planned to be performed out.

PA gp.domain.com's DNS entry will be modified to point to public IP x.x.x.5.

The public IP address x.x.x.5 will be assigned as PA external IP.

 

I have two questions about this.

 

1) How long will it take for the DNS to propagate to reflect the new IP if we make this DNS update during the cutover (6 hours)?

2) If we switch the DNS entry to the new IP x.x.x.6 will there be any issues as the same SSL certificate gp.domain.com is now active on IP x.x.x.5? Can we use the same certificate as I'm hoping it's based on DNS rather than IP?

Looking for suggestions on this.

 

Thanks in advance!!!

Rajesh Venugopal.

1 REPLY 1

L2 Linker

Any suggestions from anyone 🙂 ?

  • 388 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!