10-20-2020 10:56 PM
Hello,
I have a pair of 1010 in HA managed by FMC. The version is 6.4.0.9.
I would like to setup RA VPN.
I do not know if the customer has a CA for the certificate.
Could I use a self signed certificate form the FMC?
If I use this option I will have to manually install the certificate on the client, right?
Thanks and regards,
Konstantinos
Solved! Go to Solution.
10-20-2020 11:01 PM
10-20-2020 11:02 PM - edited 10-20-2020 11:03 PM
Hello @kostasthedelegate,
you can use a self signed just fine for VPN as long as you allow the connection to "untrusted servers" in AnyConnect Client.
You will get a certificate warning whenever you connect.
When you put the self-signed cert into the trust store it should disappear but it is not necessary.
Best regards,
Rick
10-21-2020 12:32 AM
While you can use self-signed or internal CA-signed certificates, it's strongly recommended to use a certificate issued from a trusted public CA. The only exception is for one-off lab use.
10-20-2020 11:01 PM
10-20-2020 11:02 PM - edited 10-20-2020 11:03 PM
Hello @kostasthedelegate,
you can use a self signed just fine for VPN as long as you allow the connection to "untrusted servers" in AnyConnect Client.
You will get a certificate warning whenever you connect.
When you put the self-signed cert into the trust store it should disappear but it is not necessary.
Best regards,
Rick
10-21-2020 12:32 AM
While you can use self-signed or internal CA-signed certificates, it's strongly recommended to use a certificate issued from a trusted public CA. The only exception is for one-off lab use.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide