Home
Products
Releases
Best Practices
Resources
By Type
EN
Location
Documentation Home
Palo Alto Networks
Support
Live Community
Knowledge Base
Products
Releases
Best Practices
Resources
By Type
Network Security
Cloud-Delivered Security Services
Advanced DNS Security
Advanced WildFire
Advanced Threat Prevention
Advanced URL Filtering
AI Access Security
Enterprise Data Loss Prevention
SaaS Security
IoT Security
Cloud Identity Engine
Cloud NGFW for AWS
Cloud NGFW for Azure
CN-Series
Common Services
License Activation & Subscription Management
Tenant Management
Identity & Access Management
Device Associations
FAQ
GlobalProtect
Next-Generation Firewall
PAN-OS
AIOps for NGFW
Firewalls
SD-WAN
Service Provider
Panorama
Strata Logging Service
Strata Cloud Manager
AI Runtime Security
VM-Series
Secure Access Service Edge
Common Services
License Activation & Subscription Management
Tenant Management
Identity & Access Management
Device Associations
FAQ
FedRAMP
Next-Generation CASB
Prisma Access
Autonomous DEM
Prisma Access Browser
Prisma Access Agent
Prisma SD-WAN
ION Devices
Remote Browser Isolation
Strata Cloud Manager
Strata Multitenant Cloud Manager
Cloud-Native Security
Prisma Cloud
Security Operations
Cortex XDR
Cortex XSOAR
Cortex XPANSE
Cortex XSIAM
What's New
What's New Releases
All Release Notes
View All Release Notes
Recently Updated Release Notes
Release Notes
Strata Cloud Manager Release Notes
VM-Series and Panorama Plugins Release Notes
AI-Powered Autonomous DEM Release Notes (AI-Powered ADEM)
PAN-OS Release Notes (PAN-OS 10.2)
PAN-OS Release Notes (PAN-OS 11.2)
Strata Logging Service Release Notes
PAN-OS Release Notes (PAN-OS 11.1)
Prisma Access Agent Release Notes
GlobalProtect™ App Release Notes (6.2)
See All Recently Updated Release Notes
Recently Updated Documentation
SSPM Administration
Administration
Activation & Onboarding
Prisma Access Browser Deployment
Administration
Common Services: Identity and Access
Strata Cloud Manager Getting Started
What's New in the NetSec Platform
AI-Powered ADEM Administrator’s Guide (AI-Powered ADEM)
Autonomous DEM Activation & Onboarding
See All Recent Updates
Applications and Threats Content Updates
Best Practices for Migrating to Application-Based Policy
Data Center
Decryption
DoS and Zone
Get Started
Internet Gateway Security Policy
Secure Administrative Access
Security Policy
WildFire
Zero Trust
VIEW ALL
All Release Notes
Blog
Compatibility Matrix
Experts Corner
Infographics
Licensing, Registration, and Activation
OSS Listings
Translated Documents
VIEW ALL
API Documentation
Release Notes
PAN-OS® Administrator’s Guide
PAN-OS® Administrator’s Guide
All Documentation
>
Clear
Search
Loading
Clear
Import a Private Key for IKE Gateway and Block It
Updated on
Wed Mar 26 13:28:57 PDT 2025
Focus
Download PDF
English
日本語 (Japanese)
中文 (Chinese Simplified)
繁體中文 (Chinese Traditional)
Español (Spanish)
Français (French)
한국어 (Korean)
Updated on
Wed Mar 26 13:28:57 PDT 2025
Focus
Home
PAN-OS
Certificate Management
Block Private Key Export
Import a Private Key for IKE Gateway and Block It
Download PDF
English
日本語 (Japanese)
中文 (Chinese Simplified)
繁體中文 (Chinese Traditional)
Español (Spanish)
Français (French)
한국어 (Korean)
Import a Private Key for IKE Gateway and Block It
Table of Contents
Filter
Expand All
|
Collapse All
Next-Generation Firewall Docs
Something went wrong please try again later
Something went wrong please try again later
Something went wrong please try again later
Something went wrong please try again later
Something went wrong please try again later
Previous
Import a Private Key and Block It
Next
Verify Private Key Blocking
Import a Private Key for IKE Gateway and Block It
Secure private keys for IKE Gateways that you import into PAN-OS devices by blocking key export.
Block the export of a private key to prevent its misuse after generating a certificate for IKE Gateway authentication.
Select
Network
Network Profiles
IKE Gateways
.
Add
a new IKE Gateway.
On the
General
tab, for
Authentication
, select
Certificate
.
For
Local Certificate
select
Import
or
Generate
depending on whether you want to
import an existing certificate
or create a certificate.
Enter the certificate information. If you are importing the certificate, select
Import Private Key
to activate the
Block Private Key Export
checkbox.
Select
Block Private Key Export
to prevent anyone from exporting the key.
For importing a certificate, enter and confirm the
Passphrase
and then click
OK
For generating a certificate, click
Generate
.
Enter the
Passphrase
, confirm it, and then click
OK
.
Previous
Import a Private Key and Block It
Next
Verify Private Key Blocking