Prerequisites for VPN load balancing

Review these prerequisites before configuring VPN load balancing.

  • Ensure the Firewall Threat Defense certificate includes the IP addresses or FQDNs of all directors and members to which connections are redirected. Use a Subject Alternative Name (SAN) or wildcard certificate to prevent the certificate from being flagged as untrusted.

  • Add the group URL for the VPN load-balancing group IP address to the connection profiles. Specifying a group URL eliminates the need for users to select a group at login.

  • Assign a unique IP address pool for member devices and override the IP address pool in Cloud-Delivered Firewall Management Center for each member.