cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
328
Views
0
Helpful
3
Replies

VPN Cluster and Wildcard Certificate

kennethgrande
Beginner
Beginner

Hi,

I am setting up a VPN cluster with three ASA boxes and i am wondering if anyone has any experience using a wildcard certificate with this kind of setup.

I am done with the setup and everything works fine, but as my initial setup (and the doc i have been reading) shows, the client first connect to:

cluster.domain.com

Then the master returns the address or fqdn (i am using fqdn) of the least busy asa in the cluster:

vpn01.domain.com

or

vpn02.domain.com

or

vpn03.domain.com

Thus i would need 4 certificates to meet my needs. The cluster.domain.com certificate also must be present on all 3 boxes, because the cluster ip is configured on all boxes, and the master role is shifted if one of the boxes fail.

Because of this i thought it would be a good idea to use 1 wildcard certificate (*.doman.com) on all boxes and avoid the hassle.

Any experience or recommendations?

BR,

/K

1 Accepted Solution

Accepted Solutions

I agree, i would you that for my deployment.

View solution in original post

3 Replies 3

Michal Garcarz
Cisco Employee
Cisco Employee

Hello Kenneth,

It was working for version before 9.

On ASA9 you even can not install wildcard certificate to manage ASA via ASDM, so i guess vpn loadbalancing with wildcard certificate will not work either (but i have not tested that).

And it's not a bug - it's a feature - it's a security device and wildcardard certificates are strongly discouraged

--

Michal

kennethgrande
Beginner
Beginner

I have read some more doc and it seemes like UUC certificate with multiple SANs will be the best way to go.

/K

I agree, i would you that for my deployment.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Recognize Your Peers