Kaspersky SD-WAN

Scenario: installing certificates on a CPE device with firmware version 23.07

You can install a root certificate or a certificate chain signed by a custom certification authority on a CPE device with firmware version 23.07.

Firmware version 23.07 is not fully supported by the current version of the orchestrator, therefore technical issues may occur when using this firmware version. We recommend updating the firmware of all CPE devices to the latest version.

The scenario for installing certificates on CPE devices with firmware version 23.07 involves the following steps:

  1. Uploading certificates using the orchestrator web interface

    Upload a certificate using the orchestrator web interface.

  2. Generating an URL with basic CPE device settings

    Generate a URL with basic CPE device settings, doing the following:

    1. In the Version drop-down list, select 23.07.

      Configuration web addresses are generated for each of the uploaded certificates.

    2. Click Copy next to all generated URLs.
    3. Save the copied web addresses.
  3. Installing certificates on a CPE device

    Do the following:

    1. Connect the administrator device to the LAN port of the CPE device.

      The administrator device gets an IP address and the IP address of the default gateway via DHCP. The received IP address of the default gateway is the IP address of the CPE device.

    2. From the administrator device, visit each generated web address one by one.

    The CPE device restarts after installing each certificate. Please note that the CPE device may get a new IP address after the restart, so you may need to modify the previously copied web address to install the next certificate.

See also

Scheduling firmware updates on selected CPE devices

Scheduling firmware updates on CPE devices with specific tags