Skip to main content
ck8882
Explorer
October 29, 2023
Question

How to setup custom certificate for between FGT and FMG communication

  • October 29, 2023
  • 1 reply
  • 1917 views

HI All,

 

May i know how to setup custom certificate for between FGT and FMG communication instead use built in cert? My case scenario is private CA. so currently i tried to use FAC to sign the FGT and FMG CSR.

 

I found a link https://community.fortinet.com/t5/FortiManager/Technical-Tip-Setup-custom-certificate-for-FGFM-protocol/ta-p/242730

 

However, not really understand the step. could anyone elaborate it below?? Thanks

 

Example:

FortiManager side:

 

# config system global
    set fgfm-ca-cert “RootCA” <----- May i know is this Root CA export from FAC?
    set fgfm-local-cert “cert_fmg” <--- May i know this local cert is it CSR and sign by FAC?
end

 

FortiGate side:

 

# config system central-management
    set local-cert "cert_fgt" <--- May i know this local cert is it CSR and sign by FAC?
    set ca-cert "RootCA" <----May i know is this Root CA export from FAC?
end

1 reply

ndumaj
Staff
Staff
October 29, 2023

Hello ck8882

Please review the link below the scenario should be the same:
https://community.fortinet.com/t5/FortiAuthenticator/Technical-Tip-How-to-replace-default-SSLVPN-certificate-of-a/ta-p/190394

In this case the FGT is the Webserver and FMG is the client.
On web server you have to generate a CSR singed to the Root CA in this case FAC and then you need to install the Cert singed by the FAC into FGT.
On the other hand the client FMG should have Root CA installed in order to validate the FGT server certificate.

BR


Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!