cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
676
Views
0
Helpful
6
Replies

Wildcard Cert for ASAs in failover providing SSL VPN

jgibb
Level 1
Level 1

I have a pair of ASAs in failover configuration providing VPN load-balancing. I'd like to use a cert for the inbound requests and would like to know if I can use a wildcard cert for all devices or do I need to get individual certs per device and one for the load-balaning IP.

6 Replies 6

Ivan Martinon
Level 7
Level 7

If you have a load balance setup, which is not the same as failover, you will need 3 Certs, 1 for the loadbalance ip address of FQDN which will be contained on both ASA devices and one certificate per box, pretty much your Formula will be #Certs=N+1 where N is your total number of ASA that you have.

Thanks. So basically vpn.domain.com and then vpn1.domain.com and vpn2.domain.com.

-Jake

jgibb
Level 1
Level 1

This is a test.

jgibb
Level 1
Level 1

This is another test.

jgibb
Level 1
Level 1

Three for good luck.

Jason Gervia
Cisco Employee
Cisco Employee

You have 3 options:

1) 3 certificates (1 for vpn1, vpn2, and vpn)

2) a wild card certificate

3) a UCC certificate with 3 SANs (vpn, vpn1, vpn2)