Set Up Connectivity with a SafeNet Network HSM (2024)

Set Up Connectivity with a SafeNet NetworkHSM

Updated on

Wed Jul 17 16:47:57 UTC 2024

Focus

Download PDF

Updated on

Wed Jul 17 16:47:57 UTC 2024

Focus

  1. Home
  2. PAN-OS
  3. Certificate Management
  4. Secure Keys with a Hardware Security Module
  5. Set Up Connectivity with an HSM
  6. Set Up Connectivity with a SafeNet NetworkHSM

Download PDF

Table of Contents

Previous Set Up Connectivity with an HSM
Next Set Up Connectivity with an nCipher nShield Connect HSM

To set up connectivity between the Palo AltoNetworks firewall (HSM client) and a SafeNet Network HSM server,you must specify the IP address of the server, enter a passwordfor authenticating the firewall to the server, and then registerthe firewall with the server. Before you being configuring yourHSM client, create a partition for the firewall on the HSM serverand then confirm that the SafeNet Network client version on thefirewall is compatible with your SafeNet Network HSM server (see Set UpConnectivity with an HSM).

Before the HSM and firewallconnect, the HSM authenticates the firewall based on the firewallIP address. Therefore, you must configure the firewall to use a staticIP address—not a dynamic address assigned through DHCP. Operationson the HSM stop working if the firewall IP address changes duringruntime.

HSM configurations are not synchronized betweenhigh availability (HA) firewall peers. Consequently, you must configurethe HSM separately on each peer. In active/passive HA configurations,you must manually perform one failover to individuallyconfigure and authenticate each HA peer to the HSM. After this initialmanual failover, user interaction is not required for failover to functionproperly.

  1. Define connection settings for each SafeNet Network HSM.

    1. Log in to the firewall web interface andselect

      Device

      Setup

      HSM

      .

    2. Edit the Hardware Security Module Provider settingsand set the

      Provider Configured

      to

      SafeNet NetworkHSM

      .

    3. Add

      each HSM server as follows.A high availability (HA) HSM configuration requires at least twoservers; you can have a cluster of up to 16 HSM servers. All HSMservers in the cluster must run the same SafeNet version and mustauthenticate separately. You should use a SafeNet cluster only whenyou want to replicate the keys across the cluster. Alternatively, youcan add up to 16 SafeNet HSM servers to function independently.

      1. Enter a

        Module Name

        (an ASCIIstring of up to 31 characters) for the HSM server.

      2. Enter an IPv4 address for the HSM

        Server Address

        .

    4. (

      HA only

      ) Select

      High Availability

      ,specify the

      Auto Recovery Retry

      value (maximumnumber of times the HSM client tries to recover its connection to anHSM server before failing over to an HSM HA peer server; range is0 to 500; default is 0), and enter a

      High AvailabilityGroup Name

      (an ASCII string up to 31 characters long).

      If you configure two or more HSMservers, the best practice is to enable

      High Availability

      .Otherwise the firewall does not use the additional HSM servers.

    5. Click

      OK

      and

      Commit

      your changes.

  2. (

    Optional

    ) Configure aservice route to connect to the HSM if you don’t want the firewallto connect through the Management interface (default).

    If you configure a service routefor the HSM, running the

    clear session all

    CLIcommand clears all existing HSM sessions, which brings all HSM statesdown and then up again. During the several seconds required forHSM to recover, all SSL/TLS operations will fail.

    1. Select

      Device

      Setup

      Services

      andclick

      Service Route Configuration

      .

    2. Customize

      a service route.The

      IPv4

      tab is active by default.

    3. Click

      HSM

      in the Service column.

    4. Select a

      Source Interface

      forthe HSM.

    5. Click

      OK

      and

      Commit

      your changes.

  3. Configure the firewall to authenticate to the HSM.

    1. Select

      Device

      Setup

      and

      SetupHardware Security Module

      .

    2. Select the HSM

      Server Name

      .

    3. Select

      Automatic

      or

      Manual

      foryour authentication and trust certificate.

    4. Enter the

      Administrator Password

      to authenticatethe firewall to the HSM.

    5. Click

      OK

      .

      The firewall tries to authenticate to the HSM and displaysa status message.

    6. Click

      OK

      again.

  4. Register the firewall as an HSM client with the HSM serverand assign the firewall to a partition on the HSM server.

    If the HSM has a firewall with thesame

    <cl-name>

    already registered, you mustfirst remove the duplicate registration by running the

    client delete -client

    <cl-name>

    command,where

    <cl-name>

    is the name of the registeredclient (firewall) you want to delete.

    1. Log in to the HSM from a remote system.

    2. Register the firewall using the

      client register -c

      <cl-name>

      -ip

      <fw-ip-addr>

      CLIcommand, where

      <cl-name>

      is a name that youassign to the firewall for use on the HSM and

      <fw-ip-addr>

      isthe IP address for that firewall.

    3. Assign a partition to the firewall using the

      client assignpartition -c

      <cl-name>

      -p

      <partition-name>

      CLIcommand, where

      <cl-name>

      is the name you assignedto the firewall using the

      client register

      commandand

      <partition-name>

      is the name of a previouslyconfigured partition that you want to assign to this firewall.

  5. Configure the firewall to connect to the HSM partition.

    1. Select

      Device

      Setup

      HSM

      andrefresh (

      Set Up Connectivity with a SafeNet Network HSM (1)

      ) the display.

    2. Setup HSM Partition

      (HardwareSecurity Operations settings).

    3. Enter the

      Partition Password

      to authenticatethe firewall to the partition on the HSM.

    4. Click

      OK

      .

  6. (

    HA only

    ) Repeat the previous authentication,registration, and partition connection steps to add another HSMto the existing HA group.

    If you remove an HSM from your configuration,repeat the previous partition connection step to remove the deletedHSM from the HA group.

  7. Verify firewall connectivity and authentication withthe HSM.

    1. Select

      Device

      Setup

      HSM

      andcheck the authentication and connection Status:

      • Green

        —The firewall is successfully authenticatedand connected to the HSM.
      • Red

        —The firewall failed to authenticate to the HSMor network connectivity to the HSM is down.
    2. View the following columns in Hardware Security Module Statusto determine the authentication status:

      • Serial Number

        —The serial number of the HSMpartition if the firewall successfully authenticated to the HSM.
      • Partition

        —The partition name on the HSM that is assignedto the firewall.
      • Module State

        —The current state of the HSM connection.This value is always

        Authenticated

        ifthe Hardware Security Module Status displays the HSM.

"); adBlockNotification.append($( "Thanks for visiting https://docs.paloaltonetworks.com. To improve your experience when accessing content across our site, please add the domain to the allow list on your ad blocker application." )); let adBlockNotificationClose = $("x"); adBlockNotification.prepend(adBlockNotificationClose) $('body').append(adBlockNotification); setTimeout(function (e) { adBlockNotification.addClass('open'); }, 10); adBlockNotificationClose.on('click', function (e) { adBlockNotification.removeClass('open'); }) } }, 5000)

Previous Set Up Connectivity with an HSM
Next Set Up Connectivity with an nCipher nShield Connect HSM

Recommended For You

{{ if(( raw.pantechdoctype != "techdocsAuthoredContentPage" && raw.objecttype != "Knowledge" && raw.pancommonsourcename != "TD pan.dev Docs")) { }} {{ if (raw.panbooktype) { }} {{ if (raw.panbooktype.indexOf('PANW Yellow Theme') != -1){ }}

{{ } else if (raw.panbooktype.indexOf('PANW Green Theme') != -1){ }}

{{ } else if (raw.panbooktype.indexOf('PANW Blue Theme') != -1){ }}

{{ } else { }}

{{ } }} {{ } else { }}

{{ } }} {{ } else { }} {{ if (raw.pantechdoctype == "pdf"){ }}

{{ } else if (raw.objecttype == "Knowledge") { }}

{{ } else if (raw.pancommonsourcename == "TD pan.dev Docs") { }}

{{ } else if (raw.pancommonsourcename == "LIVEcommunity Public") { }}

{{ } else { }}

{{ } }} {{ } }}

{{ if (raw.pancommonsourcename == "LIVEcommunity Public") { }}

{{ if (raw.pantechdoctype == "pdf"){ }}

{{ } }}

{{ } else { }}

{{ if (raw.pantechdoctype == "pdf"){ }}

{{ } }}

{{ } }}

{{ if (raw.pancommonsourcename != "TD pan.dev Docs"){ }} {{ if (raw.pandevdocsosversion){ }} {{ } else { }} {{ if ((_.size(raw.panosversion)>0) && !(_.isNull(raw.panconversationid )) && (!(_.isEmpty(raw.panconversationid ))) && !(_.isNull(raw.otherversions ))) { }} (See other versions) {{ } }} {{ } }} {{ } }}

{{ } }}{{ if (raw.pantechdoctype == "bookDetailPage"){ }}

{{ } }}{{ if (raw.pantechdoctype == "bookLandingPage"){ }}

{{ } }}{{ if (raw.pantechdoctype == "productLanding"){ }}

{{ } }}{{ if (raw.pantechdoctype == "techdocsAuthoredContentPage"){ }}

{{ } }}{{ if (raw.pantechdoctype == "pdf"){ }}

{{ } }}

© 2024 Palo Alto Networks, Inc. All rights reserved.

Set Up Connectivity with a SafeNet Network HSM (2024)
Top Articles
Will Data Centres Eventually Run Out Of Storage Space? - Cross-Guard
Set up your HomePod, HomePod mini, Apple TV, or iPad as a home hub - Apple Support
Craigslist Livingston Montana
Worcester Weather Underground
Bin Stores in Wisconsin
Body Rubs Austin Texas
Chase Bank Operating Hours
Nikki Catsouras Head Cut In Half
What's New on Hulu in October 2023
Irving Hac
Savage X Fenty Wiki
Craigslist Labor Gigs Albuquerque
Facebook Marketplace Charlottesville
Https E24 Ultipro Com
Interactive Maps: States where guns are sold online most
"Une héroïne" : les funérailles de Rebecca Cheptegei, athlète olympique immolée par son compagnon | TF1 INFO
Urban Dictionary: hungolomghononoloughongous
Pinellas Fire Active Calls
O'Reilly Auto Parts - Mathis, TX - Nextdoor
Homeaccess.stopandshop
Teekay Vop
Raw Manga 1000
Best Boston Pizza Places
Speedstepper
WRMJ.COM
Farm Equipment Innovations
Ocala Craigslist Com
Worthington Industries Red Jacket
Emiri's Adventures
Chase Bank Cerca De Mí
Netherforged Lavaproof Boots
Muma Eric Rice San Mateo
Scanning the Airwaves
The Closest Walmart From My Location
Indio Mall Eye Doctor
Wrigley Rooftops Promo Code
How Many Dogs Can You Have in Idaho | GetJerry.com
M Life Insider
Skyward Marshfield
RECAP: Resilient Football rallies to claim rollercoaster 24-21 victory over Clarion - Shippensburg University Athletics
Weather Underground Cedar Rapids
Rush Copley Swim Lessons
Petra Gorski Obituary (2024)
Goats For Sale On Craigslist
Tìm x , y , z :a, \(\frac{x+z+1}{x}=\frac{z+x+2}{y}=\frac{x+y-3}{z}=\)\(\frac{1}{x+y+z}\)b, 10x = 6y và \(2x^2\)\(-\) \(...
Rétrospective 2023 : une année culturelle de renaissances et de mutations
Publix Store 840
Jovan Pulitzer Telegram
WHAT WE CAN DO | Arizona Tile
Latest Posts
Article information

Author: Saturnina Altenwerth DVM

Last Updated:

Views: 6096

Rating: 4.3 / 5 (44 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Saturnina Altenwerth DVM

Birthday: 1992-08-21

Address: Apt. 237 662 Haag Mills, East Verenaport, MO 57071-5493

Phone: +331850833384

Job: District Real-Estate Architect

Hobby: Skateboarding, Taxidermy, Air sports, Painting, Knife making, Letterboxing, Inline skating

Introduction: My name is Saturnina Altenwerth DVM, I am a witty, perfect, combative, beautiful, determined, fancy, determined person who loves writing and wants to share my knowledge and understanding with you.