Raj,
this is normal behaviour if you don‘t change the default.
All your VPN certificates are issued from the internal CA of your SMS. This CA is not registered outside or known to the internet, it is for internal use.
The certificate you are scanning from the internet is from the possibilities for remote access like MOB, SSL extender, VPN clients...
If you want to get a valid certificate there, you can install your own and correct certificate from a trusted CA or you can disable all the remote access solutions on your gateway if not used.
In my book it is not a whole security risk to have the shown mismatch.
Wolfgang