EDR-G9010 Series User Manual
215
Scenario 3: X.509 with CA Mode-One CA
In X.509 mode, users have to install all certificates in all systems. To simplify this process, users can obtain
the certificate from the CA (Certificate Authority). When using certificates from the CA, each system needs
to install the same CA (.crt) to allow each system to identify different certificates from different systems.
Every certificate must be issued by the same CA. Refer to the instructions in the diagram below to learn
how to install the CA and build an IPsec VPN connection.
Scenario 4: X.509 with CA Mode-Two CAs
In some large-scale systems, users may find it difficult to get certificates from one CA and therefore need to
get certificates from different CAs. This scenario applies to the X.509 CA mode. Users have to install all CAs
(.crt) into all systems to enable every system to recognize certificates from different CAs and subsequently
allow identification of all the different systems. Refer to the instructions in the diagram below to learn how
to install the CA (.crt) and certificates (.p12) to build an IPsec VPN or OpenVPN connection.