we have a cluster of firewalls, composed of 2 nodes.
We are using Infinity Playblocks to monitor the expiration date of vpn IPSec certificate.
Infinity Playblocks informed us that the VPN certificate of the physical node-01 was expiring.
The certificate regarding the HA (the cluster object) was not about to expire. I am referring to the certificate we can see from smartconsole in the cluster object>IPSec>view certificate .
My questions are:
Is it normal that the VPN certificate of the phisical node has a different expiration date respect the HA VPN certificate?
If it is normal, which certificate is important? If we let the VPN certificate of the physical node expire, but the VPN certificate of cluster is still valid, the vpn will work?
Thank you.