Skip to main content
kzuk
New Member
September 25, 2017
Question

IPsec Site2Site Certificate

  • September 25, 2017
  • 1 reply
  • 4745 views

Hello,

 

I need to create VPN IPsec S2S tunnel with certificate authentication.

 

What i need in Subject and Key Usage/Enhanced Key Usage in that certificate?

 

For now i use certificate with address IP in Common Name and Client/Server Authentication (Enhanced Key Usage) on each sites.

 

Thats is ok?

    1 reply

    emnoc
    New Member
    September 25, 2017

    That should be fine, but  a name in the subject  field would be ideal.

     

    Ken

    kzuk
    kzukAuthor
    New Member
    September 26, 2017

    Name of what? UTM hostname? In VPN config I can't enter domain name. I can use only IP address.

    emnoc
    New Member
    September 26, 2017

    If your talking about  the CN field;  it could be something as simple as a username, hostname, email, rfc822name, etc....