In the infrastructures that I usually implement I have two connection servers and for each connection server I create a dedicated certificate where I enter the hostname as SAN (with and without domain) and as subject, the FQDN of the name I use as Round Robin DNS here is an example :