Certificate profile is not able to call when shared location is enabled in panorama

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Certificate profile is not able to call when shared location is enabled in panorama

L3 Networker

Hi Techies,

 

When shared location is enabled, I am not able to call the certificate profile in the EDL. Kindly give me the reason behind this. Because I need to use this EDL for all the location firewalls, so I don't want to do this EDL hosting service for multiple times

 AkashThangavel_0-1688970805935.png

 

AkashThangavel_0-1688971872517.png

 

 

regards,

Akash Thangavel

Network Security Engineer

 

 

 

Akash Thangavel, Network Security Engineer
1 accepted solution

Accepted Solutions

Thanks for the reply, Mr Aleksandar.Astardzhiev. From your input, I have made it possible.

 

In the common device group, the certificate profile is not showing

AkashThangavel_0-1689058923241.png

In the common device group call the common template as a reference template

AkashThangavel_1-1689059045746.png

In a common template create the certificate and certificate profile

AkashThangavel_2-1689059115167.png

Now in the common device group, the certificate profile will list, you can use it for all the device groups of the hierarchy.

AkashThangavel_3-1689059160427.png

 

regards,

Akash Thangavel

Network Security Engineer

Akash Thangavel, Network Security Engineer

View solution in original post

2 REPLIES 2

Hi @AkashThangavel ,

The checkbox for "shared" doesn't mean this object is shared between all template/template-stacks in Panorama.

Checkbox for Shared means this config will be applied in the root/shared VSYS if your firewall is configured with multi-vsys

 

Sharing certificate between different template can be tricky because there is no direction relation between templates. What you can do is:

1. Create one template in which you define some global settings that should be applied to all managed FWs, like imported certificates

2. Create template-stack that add the global settings template and the template with the rest of each FW

 

Thanks for the reply, Mr Aleksandar.Astardzhiev. From your input, I have made it possible.

 

In the common device group, the certificate profile is not showing

AkashThangavel_0-1689058923241.png

In the common device group call the common template as a reference template

AkashThangavel_1-1689059045746.png

In a common template create the certificate and certificate profile

AkashThangavel_2-1689059115167.png

Now in the common device group, the certificate profile will list, you can use it for all the device groups of the hierarchy.

AkashThangavel_3-1689059160427.png

 

regards,

Akash Thangavel

Network Security Engineer

Akash Thangavel, Network Security Engineer
  • 1 accepted solution
  • 1931 Views
  • 2 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!