Learn how to replace an expired GlobalProtect portal or gateway
certificate.
If your GlobalProtect portal or gateway certificate has expired or is about to
expire, you have several options to replace it.
For Prisma Access deployments, the portal and gateway certificates and their renewals
are managed automatically as part of the infrastructure, so you don't have to do
anything to replace an expired certificate.
If you're using third-party certificates for your portal or gateway, you will need
to manage and renew your certificates when they expire.
If the firewall is the certificate authority (CA) that issued the certificate for
your portal and gateways, the firewall replaces the expired certificate with a new
certificate that has the same attributes as the old certificate but with a different
serial number. From the web interface that is hosting the portal or gateway,
Renew the Certificate, and commit the
changes to push the certificate to the portal or the gateway.
For on-premises deployments that use third party CA-issued SSL certificates, you must
import the renewed certificate that you downloaded from your CA using the following
procedure: