Zyxel VPN certificate requirements for third-party CA

Options
Zyxel_Stanley
Zyxel_Stanley Posts: 1,481 image  Zyxel Employee
100 Answers 1000 Comments Friend Collector Eighth Anniversary
edited May 15 in Security Service

Question:
Can a Zyxel firewall establish certificate-based VPN using only Root CA and Intermediate CA certificates?

Answer:
No. Zyxel firewall requires a server certificate that includes a private key (such as .PFX/.P12) imported into My Certificates for VPN authentication. Root and Intermediate CA certificates (such as .CER) are imported into Trusted Certificates only to validate the trust chain and cannot establish the VPN tunnel by themselves.