How to Resolve VPN Certificate Issues Between uOS and ZLD Devices?

Zyxel_Cooldia
Zyxel_Cooldia Posts: 1,511  Zyxel Employee
Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments
edited August 9 in VPN

Question: 

What should I do if the self-generated certificate from uOS can't be used for IKEv2 VPN on ZLD devices?

Answer: 

If you encounter an issue where a self-generated certificate from a uOS device cannot be used for an IKEv2 VPN gateway profile on ZLD devices, follow these steps:

  1. The issue arises due to the ZLD VPN module not supporting the ECDSA algorithm in certificates.
  2. As a workaround, regenerate the certificate using the RSA algorithm.
  3. Once the RSA certificate is ready, guide users to use the "get from server" option to download the IKEv2 profile from the ATP800 device.
  4. If clients use the native Windows VPN client, provide a script installation to clients. This script can be downloaded in the wizard's final steps.
  5. If an urgent firmware update is needed to resolve this issue, initiate a request to MDM for communication with PLM to allocate resources for support.

This solution allows the users to continue using the VPN without disruptions.