We have an upcoming migration in place from CP 5600 to CP - Maestro 140.
The Maestro fabric has 2 QF 9000 apliances in a single security group and this is a single site deployment.
This will be a direct migration where maestro SG will inherit the IPschema of live 5600 GW as is.
The management server is also same so object and rules will also be same along with VPN community.
Now my query is that as i have checked the live 5600 GW Object under IPsec VPN setting i can see that there is certificate repositary which is available for the live gateways it has one defaultcert and 2 differnt certs which is being used for a DAIP VPN.
When i check maestro repository i only see one defaultcert and not the other certificates.
Please note maestro is not yet added in the VPN communities and i am assuming that once i add maestro in the VPN community and the push policy on maestro then the certificates will be visible for maestro as well.
Kindly go through and assist with some documentation to solve this.