Technical Tip: Introduction of Server Certificate Verification for Virtual Server and ZTNA Access Proxy
| Description | This article describes the addition of a server certificate verification capability for Virtual Server and ZTNA Access Proxy in FortiOS. |
| Scope | FortiOS. |
| Solution | Starting in FortiOS v7.4.9 and v7.6.3, FortiGate introduces a new capability that allows administrators to verify the server certificate of backend real servers used by Virtual Server (firewall VIP) and ZTNA Access Proxy configurations.
To support these scenarios securely, FortiOS now provides an option to ensure that the backend server presents a valid and trusted certificate before the connection is established.
The following configurations have been enhanced with the newly introduced verify-cert option:
config firewall vip edit ""
config firewall access-proxy
This prevents FortiGate from connecting to servers that present invalid or mismatched certificates, providing an additional layer of protection in external server use cases.
Recommended use:
Related documents: |
