Server Name Indication Using the CLI
Proceed with the following to configure SNI certificates on an HTTPS cluster using the CLI:
1. Configure an HTTPS cluster on Equalizer. Use the CLI syntax described in
2. Add a default certificate to the cluster if one has not been added previously. Use the CLI syn-
tax described in
"Cluster and Match Rule Commands"
3. Use the following CLI syntax to upload other certificates and the associated key files to
Equalizer's file store.
eqcli >
cert
certname
eqcli cert-
certname
>
certfile {edit
|url
}
Do the same for the associated key files:
eqcli >
cert
certname
eqcli cert-
certname
>
keyfile {edit
|url
}
4. Add an SNI object by entering the following in the HTTPS cluster context. The SNI name can
be up to 47 ASCII characters and can include period (.), dash (-), and underscore (_).
eqcli cl-HTTPS*>
sni
testsni
eqcli cl-HTTPS*-sni-tes*>
5. Now associate certificates with the new SNI by entering the following in the SNI context:
eqcli cl-NEW* >
sni
testsni
eqcli cl-NEW*-sni-tes*>
certificate
snicertificate1
eqcli cl-NEW*-sni-tes*>
where:
testsni
is the name of the SNI
snicertificate1
is the name of the certificate being added to the SNI.
Copyright © 2014 Coyote Point Systems, A Subsidiary of Fortinet, Inc.
All Rights Reserved.
365
Equalizer Administration Guide
Summary of Contents for Equalizer GX Series
Page 18: ......
Page 32: ...Overview 32 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 42: ......
Page 52: ......
Page 64: ......
Page 72: ......
Page 76: ......
Page 228: ......
Page 238: ......
Page 476: ......
Page 492: ......
Page 530: ......
Page 614: ......
Page 626: ......
Page 638: ......
Page 678: ......
Page 732: ...Using SNMP Traps 732 Copyright 2014 Coyote Point Systems A Subsidiary of Fortinet Inc ...
Page 754: ......
Page 790: ......
Page 804: ......
Page 842: ......
Page 866: ......