Devices & Servers · Firewalls, VPN gateways & routers

Stop the certificate warning on every VPN and firewall login

Every admin login and every SSL-VPN connection throws a browser warning until you fix it — and a team trained to click through warnings will click through the one that matters.

  • You are training your staff to ignore warningsA self-signed certificate throws a full interstitial on every VPN login. After a month nobody reads it, and that habit does not stay on the VPN portal.
  • Remote workers cannot spot a real attackSomeone intercepting an SSL-VPN portal produces exactly the warning your users already dismiss twice a day. A trusted certificate is what makes the fake one stand out.
  • Auditors and clients ask for this by nameISO 27001, Cyber Essentials and most client security questionnaires ask specifically whether management interfaces present trusted certificates.
  • It installs in minutes on the box you already ownAny appliance that accepts a certificate and a key takes one of these — FortiGate, pfSense, ASA, SonicWall, MikroTik, Ubiquiti.
  • $14.99for a year, Comodo PositiveSSL...
  • 69% offits list price of $49
  • Minutesdomain validated, issued the same day
  • Any applianceFortiGate, pfSense, ASA, SonicWall

Start with the box you actually own

Every one of these takes an ordinary publicly trusted certificate. Pick yours and it will jump you to the option that fits how many hostnames you need to cover.

Which of these is your estate?

The only two questions that change the answer are how many hostnames you need on the certificate, and whether your company name has to appear inside it.

1

One appliance, one hostname

The admin console and the VPN portal usually answer on the same name, so one certificate covers both. Validation is automatic, issuance takes minutes, and you paste the result straight into the appliance.

Typically: A single FortiGate, one pfSense box, one ASA, one router web UI.

Best for this COMODO

Comodo PositiveSSL Certificate

The cheapest publicly trusted certificate we sell, and nothing about an appliance needs more. Validated by email or a DNS record, then issued in minutes.

  • Domain validated · issued in minutes
  • $10,000 warranty
  • Free unlimited reissues for the whole term
from $14.99 $49 per year, before term discounts
Details
Also fine RAPIDSSL

RapidSSL Certificate

Identical in what it does. Worth taking if you prefer the RapidSSL root or already have others on it.

  • Domain validated · issued in minutes
  • $10,000 warranty
  • Free unlimited reissues for the whole term
from $16.95 $69 per year, before term discounts
Details
2

Several devices, all under one domain

Once you pass three appliances a wildcard is almost always cheaper than buying them one at a time, and it covers every hostname you add later without a reissue. Same certificate file on every box.

Typically: fw01, fw02, vpn, mgmt and everything else under acme.com.

Best for this COMODO

Comodo PositiveSSL Wildcard Certificate

Covers unlimited subdomains of one domain. Install the same file on the firewall, the VPN portal and anything you rack next month.

  • Domain validated · issued in minutes
  • Covers unlimited subdomains of the domain
  • $10,000 warranty
  • Free unlimited reissues for the whole term
from $121.98 $162.64 per year, before term discounts
Details
Also fine COMODO

Comodo EssentialSSL Wildcard Certificate

The same wildcard coverage under the EssentialSSL brand, usually a few dollars either side depending on term.

  • Domain validated · issued immediately
  • Covers unlimited subdomains of the domain
  • $10,000 warranty
from $131.61 $175.48 per year, before term discounts
Details
3

Hostnames spread across different domains

A wildcard only stretches across one domain. When the estate spans acme.com, acme.co.uk and a second brand, a multi-domain certificate lists each name explicitly and gives you one renewal date instead of five.

Typically: Different registered domains, or a mix of domains and their subdomains.

Best for this COMODO

Comodo PositiveSSL Multi-Domain Certificate

Starts with three names included and takes more as you need them. The cheapest way to put unrelated hostnames on one certificate.

  • Domain validated · issued in minutes
  • 3 hostnames included, up to 247 in total
  • $10,000 warranty
  • Free unlimited reissues for the whole term
from $114 $165 per year, before term discounts
Details
If policy needs OV COMODO

Comodo Multi-Domain SSL Certificate SAN OV

The same multi-domain coverage, but your registered company is vetted and written into the certificate.

  • Organisation validated · issued in 1-3 days
  • 3 hostnames included, up to 245 in total
  • $250,000 warranty
  • Free unlimited reissues for the whole term
from $139 $330 per year, before term discounts
Details
4

Your company name has to be inside the certificate

Domain validation proves you control the name. Organisation validation proves who you are, and puts your registered company into the certificate where an auditor can read it. Technically the encryption is identical — you are buying the vetting.

Typically: Anything driven by an internal security policy, an ISO audit or a client contract.

Best for this COMODO

Comodo InstantSSL Pro SSL Certificate

Organisation validated, your company name in the subject, and a warranty behind it. Issued in one to three working days once documents check out.

  • Organisation validated · issued in 1-3 days
  • $100,000 warranty
  • Free unlimited reissues for the whole term
from $66.93 $89.24 per year, before term discounts
Details
Lower cost OV CERTUM

Certum Trusted SSL Certificate (OV)

The same organisation vetting from Certum at a lower price point, if the brand on the root is not something your policy dictates.

  • Organisation validated · issued in 1-3 days
  • $10,000 warranty
from $41.96 $158 per year, before term discounts
Details

Three things worth reading before you order

No certificate authority can issue for an internal-only name

Since 1 November 2015 no public CA is permitted to sign fw01, firewall.local, gateway.internal or a bare IP address such as 192.168.1.1. Give the appliance a real, registered DNS name — fw01.acme.com — even if it only ever answers on the internal network. Split-horizon DNS resolves it to the private address inside and to nothing at all outside.

The warning usually survives because the chain is incomplete

Most appliances want the intermediate certificates pasted in alongside the leaf, and many silently accept just the leaf and carry on warning. If a device still shows a warning after you install, run the hostname through the SSL Checker before you open a ticket — it will tell you in one line whether the chain is the problem.

Generate the CSR on the appliance where you can

FortiGate, SonicWall, ASA and pfSense will all create the signing request and keep the private key on the box, which is safer than moving a key around. If yours cannot, our CSR generator will produce the request and the key in your browser.

Questions we get asked about this

Will this actually install on my appliance?

If it accepts a certificate and a private key — and every device listed on this page does — then yes. Some firmware wants PEM, some wants a PKCS#12 bundle; both come from the same order and we will convert it for you if the format fights you.

Do I need organisation validation for a firewall?

Technically no. The encryption is the same and browsers treat both identically. Buy OV when a policy, an auditor or a customer contract requires your company name to appear in the certificate, not because it is more secure.

Can one certificate cover both the admin console and the SSL-VPN portal?

Yes. If both answer on the same hostname a single certificate is enough. If they answer on different names, use a wildcard for one domain or a multi-domain certificate across several.

What happens at renewal?

You get a fresh certificate for the same names. You can reuse the existing key or generate a new signing request — reissues are free and unlimited for the whole term, so a device swap mid-term costs nothing.

Something else on the network?

The same certificates cover the rest of the estate. These pages start from the hardware rather than from the certificate.

Send us the hostname list and we will price it up

Tell us what each box is and which names it answers on. We come back with the cheapest combination that genuinely covers the estate — and say so if that is fewer certificates than you were about to buy.