| Description | This article describes Fortinet Security Best Practices (FSBP) SH04.2, which recommends that 'IPsec tunnels should be using valid and secure certificates'. This article also describes some of the conditions that are being checked, as well as how to satisfy this requirement. |
| Scope | FortiGate. |
| Solution |
The above FSBP requirement is triggered for review by the Security Rating Report if an administrator configures an IPsec VPN tunnel to use Signature-based (aka certificate) authentication, rather than a Pre-Shared Key for authentication to the IPsec peer.
See the following documentation for examples of such scenarios:
If no such tunnel is created (i.e. no tunnel uses certificate-based authentication), then the FortiGate automatically meets the requirement.
If there are tunnels configured with certificate-based authentication then the following are some of the conditions that will be checked:
Related document: |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2026 Fortinet, Inc. All Rights Reserved.