MTLS for HFA is indirectly enabled or disabled via option Certificate
Verification Level in HG3500 WBM. This option is located in menu:
Configuration > Security > Signaling and Payload Encryption
(SPE) > SPE Security Setup
Figure 422. Edit SPE Security Setup
When verification level is set to Trusted or Full, client certificate
is requested and verified during SSL/TLS handshake. Client certificate
must be signed by some trusted CA, whose public key certificate must
be present on GW (more CA certificates can be present).