Created on
08-09-2024
01:18 AM
Edited on
08-11-2024
10:17 PM
By
Jean-Philippe_P
Description | This article describes the FortiGate Support for Certificate Based Authentication for L2TP tunnel. |
Scope | FortiGate. |
Solution |
The Sample Topology for the Setup is as follows: ----------- AD/LDAP/CA | Client Machine (i.e Windows) <---------> Internet <---------> FGT <-- (L2TP Tunnel over IPSEC) -->
In this scenario, the client has configured certification-based authentication for the L2TP tunnel on the FortiGate. The client has installed a user certificate signed by the root CA installed on the endpoint and has imported the server certificate and CA cert to the FortiGate.
However, while attempting to establish the connection, it will be observed that the tunnel fails to establish despite the required certificate being configured on both the client & FortiGate end and also the PKI user configured under the respective user group referenced under the VPN L2TP config. This is because the FortiGate does not support certificate-based authentication for L2TP tunnels currently.
Sample config on the FortiGate: config vpn l2tp
config vpn ipsec phase1-interface
config vpn ipsec phase2-interface
|