Skip to main content
Solved

CRL Checking with Pre-Login Tunnel

  • July 14, 2023
  • 2 replies
  • 205 views

Forum|alt.badge.img+7

Hi Everyone, 

Am wanting to enable CRL Checking of device certificate for Pre-Login tunnel. 

 

I want to ensure the CRL in the certificate of the connecting NPA client will be available for verification but I'm unsure of the source doing the verification. The docs are not detailed enough.

 

Where will the CRL Checking request originate? Will it be our management plane or the one of the many NPA Gateway's the client may connect to or some other component (eg. Stitcher)?

 

Thank you

Best answer by sshiflett

@Curious,

 

Please see https://docs.netskope.com/en/netskope-help/data-security/netskope-private-access/private-access-faqs/#what-access-needs-to-be-allowed-for-npa-to-work-correctly-1

It is my understanding that the CRL request will originate from the management plane of your tenant.  The article above has a link to the support portal which provides the specific IP address(es) per management plane.  

This topic has been closed for replies.

2 replies

Forum|alt.badge.img+16
  • Netskope Employee
  • Answer
  • July 19, 2023

@Curious,

 

Please see https://docs.netskope.com/en/netskope-help/data-security/netskope-private-access/private-access-faqs/#what-access-needs-to-be-allowed-for-npa-to-work-correctly-1

It is my understanding that the CRL request will originate from the management plane of your tenant.  The article above has a link to the support portal which provides the specific IP address(es) per management plane.  


Forum|alt.badge.img+7
  • Author
  • Explorer III
  • July 24, 2023

Thanks @sshiflett those IP's listed in the KB you posted are making requests. Just the info I needed!