Hi hazeen, if you do NAT, yes you have to use an additional (official) IP The problem is, that the SA (as any device I know) has to make a mapping between the certificate and an IP address, e.g if there is a connection to the IP "A", just use the Certificate "A", if there is a connection to IP "B", just use the Certificate "B". The SA can not use the hostname of the request (https://host_A/...) as a differentiator as the hostname is known to the SA only after the SSL session is established (and the right certificate is already necessary during that setup) Cheers
... View more