02-10-2020 07:28 AM - edited 02-21-2020 09:54 AM
Hello all,
We have a Cisco Firepower 2140 and it is running VPN services for us. It is configured such that we can go to https://<hostname>/+CSCOE+/logon.html#form_title_text and login to get the client.
However, the problem is the SSL certificate for that hostname and address appears to be self-signed certificate. I'm trying to replace it with our domain wildcard certificate, however I can't seem to find the settings for it.Firewall
Any advice?
Solved! Go to Solution.
02-10-2020 09:54 AM
That's odd. I've deployed several remote access VPNs on FMC and they all worked as advertised vis-a-vis the certificate.
Certificates aren't generally cached so it shouldn't be necessary to clear client browser cache etc. when replacing the identity certificate.
You might want to open a TAC case so that the engineer can have a look in real time with you.
02-10-2020 07:39 AM
02-10-2020 08:12 AM
It's running the FTD code, I believe.
02-10-2020 08:46 AM - edited 02-10-2020 08:47 AM
If you're running Firepower Threat Defense (FTD), you set it as follows:
1. FMC-Managed: Devices > VPN > Remote Access. Select and edit the VPN Profile. Access Interfaces tab and specify the "SSL Global Identity Certificate" there. Save and deploy.
2. FDM-Managed: Device Monitoring > Remote Access VPN. Select and edit the VPN Profile. Click Nex, next and then choose "Certificate of Device Identity". Then Next > Finish and then Deploy.
If you're running ASA image then set it as described in detail here:
02-10-2020 09:14 AM
Interesting, in the FMC that's where I have it configured, but it's still showing the old certificate, even after being deployed. I had to upload the certificate to Devices -> Certificate first, in order to get it in the Global Identity Certificate drop down though.
02-10-2020 09:54 AM
That's odd. I've deployed several remote access VPNs on FMC and they all worked as advertised vis-a-vis the certificate.
Certificates aren't generally cached so it shouldn't be necessary to clear client browser cache etc. when replacing the identity certificate.
You might want to open a TAC case so that the engineer can have a look in real time with you.
02-10-2020 10:05 AM
Thanks for your help! We'll enter a case with TAC. Thankfully it's not a huge issue, just trying to unify the environment.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide