Cisco ASA Site-to-Site IPsec VPN Digital Certificates

Hello Brian

The use of a hostname is essentially there to make your life easier. According to Cisco: “Assigning a hostname identifies the host for subsequent enrollment commands, additional configuration, and provides flexibility in case the IP address of the CA server changes.”

Yes. If you change ASA hostname it will invalidate your current certificates and you’ll need to regenerate them after the name change. If you have end devices or a site-to-site VPN that relies on certificates, those connections will fail until you regenerate and re-establish the connection.

No. The names are locally significant as far as the creation of certificates is concerned.

I hope this has been helpful!

Laz