Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

Solution for SSL VPN Configuration Renewal Without Requiring User Re-Download

Hello,
I am using an SSL certificate purchased from a provider for my SSL VPN configuration. This certificate is renewed annually, but when the certificate is renewed, the configuration is updated, and as a result, my users need to re-download the VPN configuration. Since the number of users is very high, this process significantly slows down my workflow.

What is the solution to avoid requiring users to re-download the VPN configuration each year after the certificate renewal? Is there a way to automate this process or handle configuration updates without impacting users?

Thank you for your assistance!



Added TAGs
[edited by: Raphael Alganes at 10:24 AM (GMT -8) on 14 Jan 2025]
Parents Reply
  • Again: Using the yearly certificate creates a profile, which is usable only a year - And there is no real benefit of doing it with a public signed certificate. 

    You need to switch it back to the appliance certificate, which is valid for a long time (15 years or so) and redeploy it. You could redeploy it by using the Provisionen file above. 

    If needed, you can also contact your Sophos Partner for more insights. 

    __________________________________________________________________________________________________________________

Children