Hi,

I would like to upload a public SSL certificate (purchased on Certpanel, powered by Comodo) to my Watchguard (M470) in order to fix the security alert of my SSL VPN Web Page (https://xxx.xxx.xxx.xxx/sslvpn_logon.shtml).

I’ve alread tried to upload the PFX file from the import tool of the Fireware Web UI but, when i set it as the default certificate, nothing changes.

Do you have any tips?

Thanks

1 Spice up

https://www.watchguard.com/help/docs/help-center/en-US/Content/en-US/Fireware/certificates/thirdparty_webserver_certificate_c.html

Did you enable it after uploading it by selecting the third party certificate?


n
1 Spice up

To prevent the security warning you may need to also install the certificate on the devices you are using to access the web interface.
https://www.watchguard.com/help/docs/help-center/en-US/Content/en-US/Fireware/certificates/authentication_firebox_c.html

The docs are not clear on the use of PFX bundles… but do mention that the certificates must be installed in correct order to establish the certificate chain of trust.
https://www.watchguard.com/help/docs/help-center/en-US/Content/en-US/Fireware/certificates/thirdparty_webserver_certificate_c.html

Or, you can do what I do and just disable the web interface and use Watchguard System Manager - you will get no certificate warnings and IMHO, why does a firewall need a web interface anyways.

1 Spice up

He’s referring to the SSL VPN page where people would download the SSL VPN client. It’s also for the SSL VPN itself so that the client doesn’t pop a cert warning when connecting.

The management web UI itself using a self signed is fine. Admins know it’s self signed. End users getting certificate warning when connecting to the VPN however is not fine.

2 Spice ups

Hey OP! Going to pass this along to my team for more insight.

1 Spice up

Of course I’ve set mine “Third Party Certificate” but nothing changes.

Regard the other certificates that i see in the certificates list mine is like this:

Maybe the problem could be the type of the certificate?

1 Spice up

Hey OP - Curious if this resource could help! SSL Web Page - Certificate — WatchGuard Community

Hi,

the thread opened on the watchguard site it’s mine.

The videos that he recommended did not help me.

Thank you

Thanks for the confirmation - Helpful to know! Let me chat with the team to investigate further.

Sorry I don’t have anything else for you without actually looking at your config directly. If Watchguard support is involved, that’s going to be your best bet here.

Hey OP - My apologies for the delay! Did you happen to submit a support ticket already? If so, we can escalate within the support team. If not, feel free to PM me and we can get you in touch with the WatchGuard team directly.

Hi,

I’ve resolved the issue uploading another certificate.

Thank you

2 Spice ups

Appreciate the update, OP! Feel free to reach out if you need any more support in the future. Always happy to help!

1 Spice up