ssl inspection certificate - which to use
Hello all.
I am working thru the documentation about how to configure the sslvpn inspection for traffic.
I have a 'default' (trusted) cert on my 91G which shows as Fortigate_CA_SSl.
I also have purchased and installed a 'vpn.company.com' cert that my users utilize whenever connecting to my vpn - and that works well with mfa.
The documentation states that I need to import the cert to my users' devices (computer-trusted root certificates) location but doesn't mention which I should be using. It also mentions that the certificate should be the same - in both places, meaning that the cert on the firewall and computer need to have/use the same cert in order for the process to work.
I presume that this would be, should I choose to use it - the 'default' cert mentioned above. Is the correct or how do most people create/use a different cert for the ssl inspection.
I plan to create, somehow, a small group of devices to utilize this process so that I can confirm whether the process (ssl inspection) is working or not before I push out to all users ... so if anyone has a suggestion for how to do that (sample users or device/ip addresses) please feel free to share.
thanks in advance.
mark
