Double Auth certificates for SSL VPN on USG FLEX 200H

Options
Christophe31
Christophe31 Posts: 7 image  Freshman Member
First Comment Sixth Anniversary

Hello,

I'm facing a persistent issue with a 3rd party SSL certificate (Gandi) on my USG Flex 200H.

The Setup:
Certificate: Signed by Gandi (DigiCert Global Root G2 chain).
Status: I have successfully imported the Intermediate and Root CA in Trusted Certificates. Under My Certificates, the status is now OK with a complete path (3 levels).
Admin Access: The certificate works perfectly on the Web GUI (Port 10443).

The Problem:
I am using Port 12443 for 2FA / SSL VPN access and is still presenting the old "default" self-signed certificate (or throwing a certificate error).

Despite these settings, the 2FA interface does not seem to "bind" to the new certificate. Is there a specific CLI command to force the binding or a hidden menu I might have missed to ensure the 2FA/Web Portal uses the correct certificate chain?

Thanks for your help!

All Replies

  • PeterUK
    PeterUK Posts: 4,446 image  Guru Member
    250 Answers 2500 Comments Friend Collector Eighth Anniversary
    edited April 1

    At this time you can't use your certificate for SSL VPN same with 2FA on FLEX H only the Web GUI can IKEv2