SSL VPN Certificat authentication
Hi,
I want to implement SSL VPN client to site certificate authentication.
The things I tried till now :
1. Set the Fortinet_CA_SSL Proxy certificate in the ssl vpn settings as required for clients, downloaded the fortinet ca ssl proxy certificate on a client computer, installed it and tried to connect - didn't work.
2. Generate a certificate request, signed it on a windows server certificate authority and then import it on fortigate. I installed the same certificate I imported on fortigate on a client computer and tried to connect - didn't work.
I don't think I understanded well the concepts of certificates and what certificate should I use on the fortigate unite and what certificates I should use on client computers.
Another thing I tried to experiment related to certificates is setting the certificate for GUI administration of the fortigate and then importing it to a computer. I still get the warning when I connect with a browser on the fortigate. This is not very important but I thought it would be for my understanding about certificates.
The only thing that worked well for me was ssl deep inspection. I set the certificate to use for deep inspection (fortinet ca ssl proxy) and then I installed it on a computer. After that I didn't receive warnings when I open https websites, so it worked.
Can anyone give me a step by step guidance ?
Thank you very much!
