Technical Tip: Troubleshooting an IPsec signature-based tunnel not coming up with a 'The peer's certificate is not verified' FortiClient error
| Description | This article describes how to handle the 'The peer's certificate is not verified' error on FortiClient with IPsec signature-based authentication. |
| Scope | FortiGate, FortiClient, IPsec, Windows. |
| Solution | FortiClient can form a dial-up IPsec connection with FortiGate using signature-based authentication (certificates). C:\Program Files\Fortinet\FortiClient\logs\trace\FortiIKE_x.log Changing the FortiClient log level to debug is required for this step: see Technical Tip: How to enable debug log in FortiClient.
This error indicates that the FortiGate IPsec Server certificate is not trusted by the endpoint certificate authority store. Technical Tip: Using IPsec VPN certificates and peer IDs for remote users |


