What to do about recently announced certificates expiring for Palo Alto Firewalls
December 16, 04:30
0
There is quite a ruckus with the community because of Palo Alto expiring certificates on all Firewalls. The expiring certificates affect dynamically updated services like Wildfire, GlobalProtect HIP, URL filtering, DNS Security, Threat Vault, Etc. Essentially, the firewall will lose trust with Palo Alto updates services.Â
If you are not using Ansible for automated configuration management and would like to, Palo Alto has a collection available among others : Palo Alto Networks GitHub
Â
Â
A few actions must be taken for your PA NGFW:Â
Â
Scenario 1: Customers with Data redistribution and private cloud appliances must upgrade their firewalls or deploy custom certificates.Â
Â
If upgrading, a targeted version as specified in the table below is required.Â
0