Devices & Servers · Firewalls, VPN gateways & routers
Stop the certificate warning on every VPN and firewall login
Every admin login and every SSL-VPN connection throws a browser warning until you fix it — and a team trained to click through warnings will click through the one that matters.
- You are training your staff to ignore warningsA self-signed certificate throws a full interstitial on every VPN login. After a month nobody reads it, and that habit does not stay on the VPN portal.
- Remote workers cannot spot a real attackSomeone intercepting an SSL-VPN portal produces exactly the warning your users already dismiss twice a day. A trusted certificate is what makes the fake one stand out.
- Auditors and clients ask for this by nameISO 27001, Cyber Essentials and most client security questionnaires ask specifically whether management interfaces present trusted certificates.
- It installs in minutes on the box you already ownAny appliance that accepts a certificate and a key takes one of these — FortiGate, pfSense, ASA, SonicWall, MikroTik, Ubiquiti.
- $14.99for a year, Comodo PositiveSSL...
- 69% offits list price of $49
- Minutesdomain validated, issued the same day
- Any applianceFortiGate, pfSense, ASA, SonicWall
Start with the box you actually own
Every one of these takes an ordinary publicly trusted certificate. Pick yours and it will jump you to the option that fits how many hostnames you need to cover.
- Fortinet FortiGate / FortiOS fw.acme.com · vpn.acme.com One appliance, one hostname →
- SonicWall NSa, TZ and SMA sslvpn.acme.com One appliance, one hostname →
- Palo Alto PAN-OS / GlobalProtect gp.acme.com One appliance, one hostname →
- Cisco ASA, Firepower, AnyConnect vpn.acme.com One appliance, one hostname →
- pfSense and OPNsense firewall.acme.com One appliance, one hostname →
- Sophos XG and UTM utm.acme.com Several devices, all under one domain →
- WatchGuard Firebox fb.acme.com Several devices, all under one domain →
- Check Point security gateway cp.acme.com Several devices, all under one domain →
- MikroTik RouterOS router.acme.com Several devices, all under one domain →
- Ubiquiti UniFi and EdgeRouter unifi.acme.com Several devices, all under one domain →
- Zyxel USG and ATP usg.acme.com Hostnames spread across different domains →
- Juniper SRX and Pulse Secure srx.acme.com Hostnames spread across different domains →
Which of these is your estate?
The only two questions that change the answer are how many hostnames you need on the certificate, and whether your company name has to appear inside it.
One appliance, one hostname
The admin console and the VPN portal usually answer on the same name, so one certificate covers both. Validation is automatic, issuance takes minutes, and you paste the result straight into the appliance.
Typically: A single FortiGate, one pfSense box, one ASA, one router web UI.
Comodo PositiveSSL Certificate
The cheapest publicly trusted certificate we sell, and nothing about an appliance needs more. Validated by email or a DNS record, then issued in minutes.
- Domain validated · issued in minutes
- $10,000 warranty
- Free unlimited reissues for the whole term
RapidSSL Certificate
Identical in what it does. Worth taking if you prefer the RapidSSL root or already have others on it.
- Domain validated · issued in minutes
- $10,000 warranty
- Free unlimited reissues for the whole term
Several devices, all under one domain
Once you pass three appliances a wildcard is almost always cheaper than buying them one at a time, and it covers every hostname you add later without a reissue. Same certificate file on every box.
Typically: fw01, fw02, vpn, mgmt and everything else under acme.com.
Comodo PositiveSSL Wildcard Certificate
Covers unlimited subdomains of one domain. Install the same file on the firewall, the VPN portal and anything you rack next month.
- Domain validated · issued in minutes
- Covers unlimited subdomains of the domain
- $10,000 warranty
- Free unlimited reissues for the whole term
Comodo EssentialSSL Wildcard Certificate
The same wildcard coverage under the EssentialSSL brand, usually a few dollars either side depending on term.
- Domain validated · issued immediately
- Covers unlimited subdomains of the domain
- $10,000 warranty
Hostnames spread across different domains
A wildcard only stretches across one domain. When the estate spans acme.com, acme.co.uk and a second brand, a multi-domain certificate lists each name explicitly and gives you one renewal date instead of five.
Typically: Different registered domains, or a mix of domains and their subdomains.
Comodo PositiveSSL Multi-Domain Certificate
Starts with three names included and takes more as you need them. The cheapest way to put unrelated hostnames on one certificate.
- Domain validated · issued in minutes
- 3 hostnames included, up to 247 in total
- $10,000 warranty
- Free unlimited reissues for the whole term
Comodo Multi-Domain SSL Certificate SAN OV
The same multi-domain coverage, but your registered company is vetted and written into the certificate.
- Organisation validated · issued in 1-3 days
- 3 hostnames included, up to 245 in total
- $250,000 warranty
- Free unlimited reissues for the whole term
Your company name has to be inside the certificate
Domain validation proves you control the name. Organisation validation proves who you are, and puts your registered company into the certificate where an auditor can read it. Technically the encryption is identical — you are buying the vetting.
Typically: Anything driven by an internal security policy, an ISO audit or a client contract.
Comodo InstantSSL Pro SSL Certificate
Organisation validated, your company name in the subject, and a warranty behind it. Issued in one to three working days once documents check out.
- Organisation validated · issued in 1-3 days
- $100,000 warranty
- Free unlimited reissues for the whole term
Certum Trusted SSL Certificate (OV)
The same organisation vetting from Certum at a lower price point, if the brand on the root is not something your policy dictates.
- Organisation validated · issued in 1-3 days
- $10,000 warranty
Three things worth reading before you order
No certificate authority can issue for an internal-only name
Since 1 November 2015 no public CA is permitted to sign fw01, firewall.local, gateway.internal or a bare IP address such as 192.168.1.1. Give the appliance a real, registered DNS name — fw01.acme.com — even if it only ever answers on the internal network. Split-horizon DNS resolves it to the private address inside and to nothing at all outside.
The warning usually survives because the chain is incomplete
Most appliances want the intermediate certificates pasted in alongside the leaf, and many silently accept just the leaf and carry on warning. If a device still shows a warning after you install, run the hostname through the SSL Checker before you open a ticket — it will tell you in one line whether the chain is the problem.
Generate the CSR on the appliance where you can
FortiGate, SonicWall, ASA and pfSense will all create the signing request and keep the private key on the box, which is safer than moving a key around. If yours cannot, our CSR generator will produce the request and the key in your browser.
Questions we get asked about this
Will this actually install on my appliance?
If it accepts a certificate and a private key — and every device listed on this page does — then yes. Some firmware wants PEM, some wants a PKCS#12 bundle; both come from the same order and we will convert it for you if the format fights you.
Do I need organisation validation for a firewall?
Technically no. The encryption is the same and browsers treat both identically. Buy OV when a policy, an auditor or a customer contract requires your company name to appear in the certificate, not because it is more secure.
Can one certificate cover both the admin console and the SSL-VPN portal?
Yes. If both answer on the same hostname a single certificate is enough. If they answer on different names, use a wildcard for one domain or a multi-domain certificate across several.
What happens at renewal?
You get a fresh certificate for the same names. You can reuse the existing key or generate a new signing request — reissues are free and unlimited for the whole term, so a device swap mid-term costs nothing.
Something else on the network?
The same certificates cover the rest of the estate. These pages start from the hardware rather than from the certificate.
- Firewalls, VPN & routers FortiGate, SonicWall, Palo Alto, pfSense, Cisco ASA
- Voice: PBX, UCM & SBC Cisco UCM, 3CX, FreePBX, session border controllers
- Mail servers & webmail Exchange, autodiscover, Zimbra, smtp, imap
- Intranet & internal apps Staff portals, Jira, GitLab, dashboards, RDS
- NAS, hypervisor & consoles Synology, QNAP, VMware, Proxmox, iLO, iDRAC
- Web & app servers IIS, Apache, Nginx, Tomcat, load balancers
Send us the hostname list and we will price it up
Tell us what each box is and which names it answers on. We come back with the cheapest combination that genuinely covers the estate — and say so if that is fewer certificates than you were about to buy.