twice.
Without GlobalProtect:
Export the trusted root CA certificate so that you can import it into client
systems. Highlight the certificate and click Export
at the bottom of the window. Choose the PEM format.
Don’t select Export private key. The private key
should remain on the NGFW and not be exported to client
systems.
Import the trusted root CA certificate into the browser Trusted Root CA list
on the client systems for the clients to trust it. When importing into the
client browser, ensure that you add the certificate to the Trusted Root
Certification Authorities certificate store. On Windows systems, the default
import location is the Personal certificate store. You can also simplify
this process by using a centralized deployment option, such as an Active
Directory Group Policy Object (GPO).