Refresh SSH host keys and configure various SSH connection
parameters with an HA SSH service profile.
| Where Can I Use This? | What Do I Need? |
- NGFW (Managed by Strata Cloud Manager)
- NGFW (Managed by PAN-OS or Panorama)
|
For Strata Cloud Manager managed NGFWs:
|
All Palo Alto Networks firewalls come with
Secure Shell (SSH) pre-configured, and the high availability (HA)
firewalls can act as SSH server and SSH client simultaneously. When
you configure
active/passive or
active/active HA, you
can enable encryption for the HA1 (control link) connection between
the HA firewalls. We recommend you secure the HA1 traffic between
the HA peers with encryption, particularly if the firewalls aren’t
located in the same site. After you enable encryption on the HA1
control link, you can use the CLI to
create an SSH service profile and
secure the connection between the HA firewalls.
SSH service
profiles enable you to change the default host key type, generate a
new pair of public and private SSH host keys for the HA1 control
link, and configure other SSH HA1 settings. You can apply the new
host keys and configured settings to the firewalls without restarting
the HA peers. The firewall will reestablish HA1 sessions with its
peer to synchronize the configuration changes. It also generates system
logs (subtype is ha) for reestablishing
HA1 and HA1-backup sessions.
You must enable encryption
and it must be functioning properly on an HA pair before you can
perform the following tasks.
If you are configuring
the HA1 control link in
FIPS-CC mode, you must
set automatic rekeying parameters for session keys.
To
use the same SSH connection settings for each Dedicated Log Collector
(M-series or Panorama virtual appliance in Log Collector mode) in
a
Collector Group, configure
an SSH service profile from the Panorama management server,
Commit the changes to Panorama, and then
Push the
configuration to the Log Collectors. You can use the
set log-collector-group <name> general-setting management ssh commands.