Skip to main content
dnayak_FTNT
Staff
Staff
August 7, 2015

Technical Note: SSL VPN based on both LDAP and certificate authentication

  • August 7, 2015
  • 0 replies
  • 6963 views
Description
This article addresses the configuration where clients are to connect to SSL VPN using both their domain credentials and SSL user certificate.

It does not cover general SSL VPN configuration and LDAP configuration/integration in the FortiGate as it is assumed they are already in place.

Solution
Import the user certificate in the browser (IE). The user certificate will always be present in “Personnel” tab as shown below.
sinamdar_FD36844_tn_FD36844-1.jpg
Also, import user’s CA certificate in the browser.
sinamdar_FD36844_tn_FD36844-2.jpg
Import the server certificate and SSL VPN user’s CA certificate in the FortiGate.
sinamdar_FD36844_tn_FD36844-3.jpg
Enable the “require client certificate” option and specify the SSL VPN server certificate in SSL VPN settings. Under the users/groups section, specify LDAP users/groups. This will enable both LDAP and certificate authentication.
sinamdar_FD36844_tn_FD36844-4.jpg
Use the user certificate and LDAP credentials on the FortiClient as shown below:
sinamdar_FD36844_tn_FD36844-5.jpg
The client will now be able to connect to SSL VPN using both their domain credentials and their user certificate.

Related Articles

Technical Note: SSL VPN - Certificate Based Authentication

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!