Confirm that the appropriate interfaces are configured as either virtual wire,
Layer 2, or Layer 3 interfaces.
Select , and then check the Interface Type
column for Virtual Wire, Layer
2, or Layer 3. Select an
Interface to modify its configuration.
Configure the Forward Trust certificate that the
NGFW presents
to clients after a trusted CA signs the server certificate.
Distribute the Forward Trust certificate to client system certificate
stores.
SKIP THIS STEP if you're using an enterprise-CA signed
certificate as the Forward Trust certificate and the client systems
already have the enterprise CA installed in their local trusted root CA
list. (The client systems trust the subordinate CA certificates
generated on the NGFW because the enterprise trusted root
CA has signed them.)
If you don't install the Forward Trust certificate on
client systems, users see certificate warnings for each SSL site they
visit.
Configure the Forward Untrust certificate.
Use the same Forward Untrust certificate for each NGFW.
Clients receive a certificate warning when attempting to access sites with
untrusted certificates.
Select , and then click
Generate.
Enter a
Certificate Name.
Enter a
Common Name. Leave
Signed
By blank.
Select the
Certificate Authority option.
Generate the certificate.
Designate the certificate as the Forward Untrust certificate.
Select , and then select the Forward Untrust
certificate.
The Certificate information dialog opens.
Select the Forward Untrust Certificate
option.
Click OK.
-