- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: Wildcard Certificate IPsec VPN repository
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Wildcard Certificate IPsec VPN repository
Hi All,
Has anyone tried importing a wild card certificate into the IPsec VPN repository?. I am looking to change the default certificate which is shown to VPN clients, (General Properties > VPN Clients > "the gateway authenticates with this certificate".
We have a client using a wildcard cert from GoDaddy for other services. I tried following the documentation in terms of adding the cert CA and intermediate CA and creating the CSR request under the IPSec VPN repository.
The challenge is I cannot use this enrollment request since this task is already down outside the firewall. Is there a way to import the certificate since it throws an error on Smart Console (R80.20 mgmt and gw). "the new issued certificate does not match the enrollment request" which is expected.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Do you have the mobile access blade enabled on the gateway?
If you have you will be able to import the p.12 from the relative blade settings and then remote access client will use this certificate to authenticate from the gateway , at least this is what tac told me in one sr since I have the same request , but at the moment I don' t know if you don't have the mobile access blade enabled
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Do you have the mobile access blade enabled on the gateway?
If you have you will be able to import the p.12 from the relative blade settings and then remote access client will use this certificate to authenticate from the gateway , at least this is what tac told me in one sr since I have the same request , but at the moment I don' t know if you don't have the mobile access blade enabled
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Is there a way to confirm that the remote access clients are now using the same certificate as one applied in the mobile access settings?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
you can delete the site on one of the client using the endpoint/win10 plugin and see wich certificate is pronted
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Saved me a TAC case 😉
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
glad to help 🙂
