Configure Certificate on the Device Using CLI Commands
Table of Contents
Expand All
|
Collapse All
Prisma SD-WAN Docs
-
-
-
-
- AWS Transit Gateway
- Azure vWAN
- Azure vWAN with vION
- ChatBot for MS Teams
- ChatBot for Slack
- CloudBlades Integration with Prisma Access
- GCP NCC
- Service Now
- Zoom QSS
- Zscaler Internet Access
-
-
- ION 5.2
- ION 5.3
- ION 5.4
- ION 5.5
- ION 5.6
- ION 6.0
- ION 6.1
- ION 6.2
- ION 6.3
- ION 6.4
- New Features Guide
- On-Premises Controller
- Prisma Access CloudBlade Cloud Managed
- Prisma Access CloudBlade Panorama Managed
- Prisma SD-WAN CloudBlades
Configure Certificate on the Device Using CLI Commands
Update the CA chain on the ION device version older than 6.2.3-b2
release.
Update the CA chain on ION devices running on software version older than 6.2.3-b2
release.
- Set up the controller chain file in the devices.Copy the ca chain file from the controller:/home/ubuntu/certs/cachain.cgnx.net.pemReplace or create the following files in the device, contact your Palo Alto Networks representative to update the CA certificate on the ION device./config/certs/controller_ca_chain.pem/etc/certs/controller_ca_chain.pemAdd the static host details to the device:config static host add ip <Controller_IP> name controller.local.cgnx.net config static host add ip <Controller_IP> names locator.cgnx.net config static host add ip <Controller_IP> names mfg.local.cgnx.net config static host add ip <Controller_IP> names vmfg.local.cgnx.net config static host add ip <Controller_IP> names toolkitsessions.local.cgnx.netVerify that the controller details are reflected in the device by executing the command dump overview.After verification, create machine by accessing the controller using the device ID.