Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Not applicable

Can the same SSL Certificate be used on 2 firewalls????

We have 2 firewalls physically located in 2 separate cities. Firewall #1 is our production device and firewall #2 is used for DR only. Firewall #1 has a valid certificate installed on it (signed by Verisign) and we used a Domain Name for certificate validation. If our production firewall (#1) were to encounter an issue, our plan is to change the public DNS IP associated with our ' A' record and point it to to our DR firewall (#2). My thought is to have the same certificate on firewall #2 which would avoid purchasing a separate certificate. Is there a way to export the certificate from firewall #1 and import into firewall #2? This certificate would be used for SSL VPN access.
3 REPLIES 3
jmac
New Contributor

You should be able to export the configuration of firewall 1 (without a password) and extract the section containing the certificate and private key. You can then upload it as a command file in the GUI or execute it directly in the CLI.
emnoc
Esteemed Contributor III

yes that should work and would be smart. You might want to research wildcards certs and see if this might be beneficial if you need to run active/active between production vrs DR site. Wildcards might help in this situation.

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
gunthnp
New Contributor

You need to work with your CA to do this right. Have them issues a cert for the same dns and both IPs this is common.
Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors