Why is the SecuExtender VPN client receiving a 'Self-signed certificate not accepted' error?

Options
Zyxel_Emily
Zyxel_Emily Posts: 1,491 image  Zyxel Employee
Zyxel Certified Network Administrator - Security Zyxel Certified Sales Associate 100 Answers 1000 Comments
edited May 26 in VPN

Question:
When using the SecuExtender VPN client with the USG FLEX series, such as the USG FLEX 200, you may encounter the error: "Self-signed certificate not accepted for CN = nebula...". This issue often occurs if the VPN certificate has expired or needs renewal.

Answer:

  1. On Nebula, navigate to Configuration > Remote Access VPN.
  2. Disable and then re-enable the Remote Access VPN feature. This action will renew the certificate.
  3. Reboot the USG FLEX device manually.
  4. Download the new VPN configuration script provided by the device after the certificate is renewed.
  5. Import the updated VPN script into the SecuExtender VPN client.
  6. Attempt to reconnect to the VPN using SecuExtender.