Created on
05-08-2023
11:39 PM
Edited on
04-25-2025
03:38 AM
By
Jean-Philippe_P
Description | This article describes how to enable SSL VPN client certificate authentication only for a specific user/group. |
Scope | FortiGate. |
Solution |
config vpn ssl settings config authentication-rule edit <no> <----- User group that should connect with LDAP client certificate authentication. set client-cert en <----- Default is disabled. next end
Note: If the users are using certificate authentication in web mode and 'require client certificate' is disabled globally, then it does not work. To work in web mode, 'require client certificate' should be enabled.
Related document: Configuring the SSL VPN settings to require a client certificate |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.