Your fix worked. It's odd that if they would want you to pick a permenant FQDN for the gateway-va for external/internal access but not fix this certificate as a part of the setup (that or I misundertand the configuration guide).
Thanks for your help.