Skip to main content
Bhuvanesh
Staff
Staff
January 20, 2026

Technical Tip: Site-to-Site IPsec VPN Configuration with Certificate-Based Authentication.

  • January 20, 2026
  • 0 replies
  • 1491 views
Description This article describes how to configure a Site-to-Site IPsec VPN using certificate-based authentication on FortiGate firewalls.
Instead of using a pre-shared key (PSK), the VPN peers authenticate each other using X.509 certificates signed by a trusted Root Certificate Authority (CA).
Scope FortiGate.
Solution

Step 1: Create or obtain the Root CA Certificate and then import it under Create/Import -> Remote Certificate

Step 2: Obtain a child/server/client certificate with .p12 format and import it under Create/Import -> Certificate

Choose with Certificate + key or Certificate with .p12 Format. 

 

Screenshot 2026-01-02 154203.png

 

Screenshot 2026-01-02 154157.png

 

Here, the Root CA is tftpFortinet, and the Server/Entity/Client Certificate is FortiGateCert_cert.

 

Root CA.png

 

The same procedure must be followed on the peer device.

 

Step 3. Configure IPSec tunnels on both the Firewalls, and then choose the authentication as Signature instead of Pre-Shared Key. 

Technical Tip: How to set up IPsec VPN between two FortiGates (Using VPN Setup wizard and custom profile)

 

Local Firewall:

  1. Choose the Entity Certificate as the imported Server Certificate, which has a .p12 format.
 

Root CA_upd.png

 

  1. For the Peer Certificate, create a new PKI user, enter the required name, and select the imported Root CA

 

Root CA___.png

 

All other configurations remain the same; only the authentication method should be changed from Pre-Shared Key to Signature.

 

The same steps must be followed for the Remote Firewall

 

Sample output:

Use the following CLI commands to verify tunnel status:

 

Screenshot 2026-01-02 Root.png

 

IPSec using FortiGate default certificates:

Troubleshooting Tip: IPSec tunnel with certificate-based authentication between two FortiGates

Troubleshooting Tip: IPsec certificate based VPN, failed to load private key /etc/cert/local/

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.