Skip to main content
1mm
Explorer III
October 18, 2023
Question

Fortigate and ACME

  • October 18, 2023
  • 5 replies
  • 2907 views

Hello,

 

We have deployed Fortigate in Azure, we have configured fortivpn for remote access vpn. We use letsencrypt certificate for VPN. This certificate should renew automatically because we use ACME. 

https://docs.fortinet.com/document/fortigate/7.0.0/new-features/822087/acme-certificate-support#:~:text=The%20ACME%20interface%20can%20later,to%20the%20Local%20Certificate%20list.

 

For some reasons I would like to change ACME interface on my fortigate, but I cant:

 

acme.png

 

acme2.png

 

how I can change interface? 

5 replies

DanNSits
Explorer III
October 18, 2023

Did you already try to change it via CLI?

config system acme
mle2802
Staff
Staff
October 18, 2023

Hi @1mm,

Can you try the following command instead

config system acme     set interface port1 end


Regards,
Minh

1mm
1mmAuthor
Explorer III
October 18, 2023

Hello, will try and let you know. Thanks. 

hbac
Staff
Staff
October 18, 2023

Hi @1mm,

 

Please make sure that 'Redirect HTTP to SSL-VPN' is not enabled under SSL-VPN settings and make sure port 443 and 80 are not being used for GUI access or VIPs. Refer document for more information on ACME : https://docs.fortinet.com/document/fortigate/7.2.4/administration-guide/822087/automatically-provision-a-certificate

 

Regards, 

1mm
1mmAuthor
Explorer III
October 18, 2023

Hello @hbac, thanks for your reply.

There are no any VIPs, just SSL vpn running on 443 port.

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!