Skip to main content
mbr13
New Member
March 26, 2020
Question

Certificate based Authentification

  • March 26, 2020
  • 1 reply
  • 1628 views

Hello Guys,

I'm currently working on establishing a site-to-site-VPN connection using the IPSec protocol and two Fortigate-Firewalls.

Got my certificate based authentification working, using those instructions:

https://docs.fortinet.com/document/fortigate/5.6.0/cookbook/850466/obtaining-the-necessary-certificates

 

Now my question is: w

Why do I need two CA-Certificates to establish the VPN connection?

Would this also work if I only had one CA-Certificate, that would sign both of the client/firewall-certificates?

 

Thanks in advance,

 

Marcel

    1 reply

    mbr13
    mbr13Author
    New Member
    March 31, 2020

    bump

    Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
    Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!