cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
673
Views
0
Helpful
6
Replies

Wildcard Cert for ASAs in failover providing SSL VPN

jgibb
Level 1
Level 1

I have a pair of ASAs in failover configuration providing VPN load-balancing. I'd like to use a cert for the inbound requests and would like to know if I can use a wildcard cert for all devices or do I need to get individual certs per device and one for the load-balaning IP.

6 Replies 6

Ivan Martinon
Level 7
Level 7

If you have a load balance setup, which is not the same as failover, you will need 3 Certs, 1 for the loadbalance ip address of FQDN which will be contained on both ASA devices and one certificate per box, pretty much your Formula will be #Certs=N+1 where N is your total number of ASA that you have.

Thanks. So basically vpn.domain.com and then vpn1.domain.com and vpn2.domain.com.

-Jake

jgibb
Level 1
Level 1

This is a test.

jgibb
Level 1
Level 1

This is another test.

jgibb
Level 1
Level 1

Three for good luck.

Jason Gervia
Cisco Employee
Cisco Employee

You have 3 options:

1) 3 certificates (1 for vpn1, vpn2, and vpn)

2) a wild card certificate

3) a UCC certificate with 3 SANs (vpn, vpn1, vpn2)

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: