3.3.1 Creating an A record / Requesting a certificate
The AGW must be accessible from end users' browsers. An A-record is required for this purpose. The associated SSL certificate must be stored on the AGW so that the browsers of end users classify the connection as secure. The certificate can originate from an internal CA.
When using a cluster (see 4.7), the certificate is shared and must cover the floating IP entry.