Important note about SSL VPN compatibility for 20.0 MR1 with EoL SFOS versions and UTM9 OS. Learn more in the release notes.

Solution for SSL VPN Configuration Renewal Without Requiring User Re-Download

Hello,
I am using an SSL certificate purchased from a provider for my SSL VPN configuration. This certificate is renewed annually, but when the certificate is renewed, the configuration is updated, and as a result, my users need to re-download the VPN configuration. Since the number of users is very high, this process significantly slows down my workflow.

What is the solution to avoid requiring users to re-download the VPN configuration each year after the certificate renewal? Is there a way to automate this process or handle configuration updates without impacting users?

Thank you for your assistance!



Added TAGs
[edited by: Raphael Alganes at 10:24 AM (GMT -8) on 14 Jan 2025]
Parents Reply
  • Why would you publish this? 

    Let me recap what is important: 

    1 User logins to VPN Portal: Here you use your public cert, as it is only the VPN Portal via HTTPS.
    2 User downloads the OVPN File: Here you get the public key of the self-signed cert + a User cert + private key for user cert. (That is included in the OVPN). 
    3 User imports this OVPN into a VPN Client. 

    If you use Sophos Connect VPN Client, you could replace the step 1 & 2 with the provisioning file. 

    __________________________________________________________________________________________________________________

Children