Skip to main content
dtehrani
New Member
August 24, 2015
Question

Forticlient Certificates and OFF-Net behaviour.

  • August 24, 2015
  • 2 replies
  • 3112 views

Hi Guys, I am new to the forums. During the last weeks we have installed a Fortigate Cluster. (for the first time, I admit in the beginning.)

 

I wish to find some exchange on some ideas we expect to do with Forticlient and some "Yes" or "No's" from the experienced users.

 

Certificate Authentication (+other credentials)

Is there any experience in authenticating via IPSec with a computer certificate, issued from the Windows Domain (via GPO)?

(It is working for us with User Certificates, no success for the computer certificate)

 

Forticlient Off-Net behaviour

What is the intended behaviour for Forticlient: "Auto-connect when Off-Net: This option allows the FortiClient to autoconnect to a VPN even when it has an off-net status." (from the product description)

Would this block traffic other than to the VPN Site? This is what I would like to achieve, any experience in a similar setup?

 

Thanks for sharing your thoughts.

Regards,

Darius

Environment: FortiOS  5.24 + Forticlient 5.24 Windows 2012 Domain, Windows Clients.

    2 replies

    Chris_Lin_FTNT
    Staff
    Staff
    September 1, 2015

    Certificate Authentication (+other credentials)

    Two questions:

    1. Is that certificate accessible to FortiClient IPSec, including private key, etc.

    2. Does it have proper usage for IPSec?

     

    When you connect, what does FortiGate debug say?

    Chris_Lin_FTNT
    Staff
    Staff
    September 1, 2015

    Forticlient Off-Net behaviour

    Yes. It can block traffic.

     

    Make that IPSec off-net autoconnect, disable disconnect, and use IPSec settings

    <ike_settings> <implied_SPDO>1</implied_SPDO> </ike_settings>

    Then even before IPSec is connected, other traffic will be blocked.

     

    But there are many corner cases, e.g., you may need to acknowledge a login web page before you have Internet access, PC wake up from sleep, it takes actually time to determine on-net/off-net. So this feature is not very reliable.

    Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!