cancel
Showing results for 
Search instead for 
Did you mean: 

Enquiries on Certificates for SSL VPN running on HA Cluster

michael.saw_
Regular Contributor

Enquiries on Certificates for SSL VPN running on HA Cluster

Hi all,

 

If we have a pair of SSL VPN in a cluster, how should we upload the CA cert?

Do we use the same cert of both SSL VPN?

 

Is there a kb or doc link on this?

Pls share Smiley Happy

4 REPLIES 4
jayLaiz_
Super Contributor

Re: Enquiries on Certificates for SSL VPN running on HA Cluster

Hi Michael,

 

you need a comon certificate for both nodes for example, if users access your cluster external VIP from outside and the hostname is https://sa.test.net, you need a device cert for sa.test.net only

 

Thanks,

Jay

michael.saw_
Regular Contributor

Re: Enquiries on Certificates for SSL VPN running on HA Cluster

Hi Jay,

Can we load it into the active node and it will automatically be synchronized to the passive one?
jayLaiz_
Super Contributor

Re: Enquiries on Certificates for SSL VPN running on HA Cluster

Hi Michael,

 

Yes it will synchronize the certificate between the nodes

 

Regards,

Jay

michael.saw_
Regular Contributor

Re: Enquiries on Certificates for SSL VPN running on HA Cluster

Thanks, Jay.

I remembered that there are some configs that wun be sync'ed like IP addressings and something...