service certificate push from panorama to managed firewalls eg: vpn

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

service certificate push from panorama to managed firewalls eg: vpn

L3 Networker

Hi folks,

 

We have panorama and few pairs to managed firewalls being managed by panorama,

Under the Templates, created CSR and imported the signed CA and pushed it to specific template firewall(say FW01-active), the managed firewall local configurations displays the new certificate, however, on the FW02-passive one the certificate did not sync.

Do we need to separately push to FW02 template, by creating csr and same procedure? since its the vpn service certificate, it should sync from the active-FW01.

Note: Templates care configured for each firewall separate (eg: FW01-Template ; FW02 Template so on)

 

 

3 REPLIES 3

Cyber Elite
Cyber Elite

Hello @zaidshaikh

 

thanks for post.

 

Based on documentation: What Doesn't Sync in Active/Passive HA? most of the certificates and certificate related configuration does not sync in HA deployment. It specifically does not call out a certificate used for VPN, however personally I believe it is a root cause. I would add the certificate to the Template associated with FW02.

 

Kind Regards

Pavel

Help the community: Like helpful comments and mark solutions.

Hi Pavel,

 

Thank you for the response.

Presently the panorama is provisioned to managed 4 pairs of firewall, each pair is in A-P. What i found is that for each firewall let say FW01-Active has a individual Template and Template stack similarly for FW02-passive has individual T and TS.

Now with regards to s2s vpn cert based authenticate, i want to know if i generate a csr from each firewall template with similar CN: contoso.abc.com and import it into each firewall Template and Push.

Will the VPN will work after failover is trigerred? when old passive FW02 becomes new active? Assuming that similar CN will suffice for th tunnel to get establish with no issues.

 

Hi Pavel,

I was able to get the answer from TAC after testing it in LAB:

Each FW template can have separate csr should be generated with the same Common Name in order for the service certificates to work properly during failover. Hence, the peer auth happens based on CN name which is identical in both FW01 and FW02.

 

  • 373 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!