The SSL-VPN tab has three sections
Settings:
If SSL-VPN is not active then you need to activate it in AP Policy, refer SSL-VPN for more details.
Certificate:
In the Certificate section, from the Client Certificate drop-down list, select the certificate you want used for the policy.
The CT VPN supports the certificate option where as NX VPN does not.
Others:
click the Allow Security Tunnel Access for LAN2/LAN3/Lan4
Click OK, to save the changes.