Certificate
Use this option to authenticate users with trusted certificate authorities (CAs).
When you choose Certificate, each user is authenticated with a client certificate. The client certificate must be configured on VPN client endpoints. By default, the user name is derived from the client certificate fields CN and OU. If the user name is specified in other fields in the client certificate, use the Primary field to authenticate and Secondary field to authenticate field to map appropriate fields.
Select Multiple Certificates authentication to authenticate the VPN client using the machine and user certificates.
If have enabled Multiple Certificates authentication, you can select one of the following certificates to map the username and authenticate the VPN user:
- First Cert—Select this option to map the username from the machine certificate sent from the VPN client.
- Second Cert—Select this option to map the username from the user certificate sent from the client.
Note: If you do not enable multiple certificate authentication, the user certificate (second certificate) is used for authentication by default.