PANOS Global Protect Azure SAML w/ Self-Signed Certifcate on Firewall

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

PANOS Global Protect Azure SAML w/ Self-Signed Certifcate on Firewall

L2 Linker

Looking to see if anyone has done the above configuration.  Essentially 2 sets of firewalls, 2 locations, managed in Panorama.  I created the portal on 1 set, using a self-signed certificate on the firewall (used the PA-VM as the CA and then issued itself a certificate).  Created 1 gateway on the local VM, then planned to issue the remote VM a certificate as well and then use that on the gateway on that firewall.  

 

On the Azure side, I set this up as a standard SAML integration, I just uploaded the certificate (the one that was signed by the CA) into Azure.  I should be able to test in the next few days but wanted to see if anyone had any feedback.  

 

 

2 REPLIES 2

L7 Applicator

Based on my understanding, you have created a Global Protect Portal on one PA-VM & Gateway on the other PA-VM. If yes, this normally works as this is more common architecture when you have multi-site VPN. Only concerning part is use of self-signed certificate. Is this your internal VPN or test VPN. Because client should trust the certificate else they will get self-signed certificate related errors. 

M

Check out my YouTube channel - https://www.youtube.com/@NetworkTalks

L2 Linker

Thanks for replying.  Using a self-signed certificate w/ the PA-VM as the CA, then creating a certificate w/ the FQDN using itself as the one that signs it.  Imported that certificate into Azure and set the client to trust the certificate so no warnings (plan is to push the certificate and GP client out via MDM).  This seemed to work ok and testing has been successful. 

 

Trying to integrate the 2nd PA-VM now.  The setup went mostly the same, but trying to figure out the certificates for the 2nd firewall.  Would i need to export the root from the first firewall and issue the 2nd certificate from that firewall as well and then export them and import them into the 2nd unit?  Then setup a 2nd Enterprise Application in Azure using that new certificate?  Same for the portal to gateway cookie certificate?  

 

There will be public FQDNs for both sites  but at the moment the Public CA that is being used doesn't offer ACME and the goal was to be able to extend the certificate expiration dates to account for the looming changes.

  • 196 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!