03-22-2013 07:44 PM
You can generate a certificate in PEM ironports and the same use in other Ironports
Solved! Go to Solution.
03-27-2013 02:35 AM
Hello Issael,
that is possible and quiet often used, i.e with a wildcard certificate where CN=*.example.com supporting any given interface name on each appliance, mail1.example.com, mail2.example.com, ....etc. If that is too expensive, and you are using only one IP for outbound traffic (i.e. behind a NAT), then use a normal cerificate and assign the same interface name to all appliances where traffic goes out. You could also use the subjectAltName in the certificate to specify the other appliances, but that is quiet complex and needs a specific look at the individual network setup.
Hope that helps,
Andreas
03-27-2013 02:35 AM
Hello Issael,
that is possible and quiet often used, i.e with a wildcard certificate where CN=*.example.com supporting any given interface name on each appliance, mail1.example.com, mail2.example.com, ....etc. If that is too expensive, and you are using only one IP for outbound traffic (i.e. behind a NAT), then use a normal cerificate and assign the same interface name to all appliances where traffic goes out. You could also use the subjectAltName in the certificate to specify the other appliances, but that is quiet complex and needs a specific look at the individual network setup.
Hope that helps,
Andreas
03-27-2013 08:21 AM
Hello Andreas
thank you very much for your feedback.
regards
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide