Hi there,
I am accessing my FortiGate web GUI using a public IP address.
My question is, whenever I access the web GUI using the domain name, it does not show any error regarding an unsecured connection. However, whenever I try to access it using the IP address, it shows an unsecured connection error.
I want the FortiGate to only be accessible via the domain name with a secured, encrypted connection, and not via the IP address
Solved! Go to Solution.
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hello @Daniyal007 ,
If you can add the IP address of FortiGate to the San area. You will not see a warning when you connect with the IP address.
Hello @Daniyal007,
This is normal behavior. If your fqdn and certificate san or cn area are matched this warning disappears.
Probably your certificate san or cn area does not include your IP address. Because of that, you see a warning if you connect with an IP address instead of fqdn.
There is no option for just connecting with fqdn on Fortigate. You need to resume this way.
so i have to add CN as domain name and ip address as SAN right?
Hello @Daniyal007 ,
If you can add the IP address of FortiGate to the San area. You will not see a warning when you connect with the IP address.
my main focus is not to get warning when i access fortigate.
so according to your recommendation i have to add domain name in CN and ip address in SAN . thats how i dont get waring even when i access with domain or ip Right?
Hi @Daniyal007,
Yes, you are right. Please refer to https://community.fortinet.com/t5/FortiGate/Technical-Tip-Adding-SAN-Subject-Alternative-Name-while/...
Regards,
Created on 05-13-2024 07:14 AM Edited on 05-13-2024 07:15 AM
Make sure both are in the SAN.
Modern browsers validate addresses against SAN only, CN is ignored. (It used to be used as a backup attribute to check if a SAN doesn't exist in the cert, but that should no longer be the case for any major browser, AFAIK(
ok so if i have 50 sites means 50 firewall deployed so i have to buy 50 certificates with san entries included or is their any way to add 50 site ip address in san against one domain??
Created on 05-17-2024 12:17 AM Edited on 05-17-2024 12:20 AM
Hi @Daniyal007 ,
As I know, you can add all domain addresses to the SAN area in one certificate. You don't need to buy a certificate for every domain name.
PS.
I found a document about the SAN certificate. I think good information includes about san.
https://www.thawte.com/resources/pdfs/Thawte_Multiuse_SSL_WP.pdf
The validity of the certificate is evaluated based on whether the website address in the address bar matches the identity claimed in the certificate (in "subject alternative name" (SAN) attribute), among other things.
Your description is a strong indication that the current certificate has the domain name included in the SAN, but not the IP.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1632 | |
1063 | |
749 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.