Created on
08-14-2024
11:33 AM
Edited on
08-15-2024
09:15 PM
By
Anthony_E
Description |
This article describes key information about FortiToken-300/310. |
Scope |
Understanding FortiToken-300/310 and their deployment context. |
Solution |
FortiToken-300/310 is a USB device that essentially serves as a portable personal certificate store, and is physically connected to the user's computer for client certificate-based identification/authentication. The device can not be registered with the firewall or linked/attached to a specific user as the other token models.
Important Note: Each FortiToken-300/310 owner is expected to have a unique non-exportable certificate to provide its identity.
Download the necessary software and guidelines to prepare for customizing these tokens to secure the infrastructure.
The PKI certificate can be attached to a policy as a second-layer of authentication.
client(FTK310_certificate)---------[FGT---PolicyX(userme+PKI_Cert)]----------------------[Secure_Segment]
Below is an example of the process of trust relationship configuration on FortiGate.
Applicable Scenario A: Technical Tip: PKI peer user creation for certificate authentication. Applicable Scenario B: Technical Tip: Using Certificates to authenticate users in SSL VPN.
Once the token FortiToken300_310 is plugged into the PC, the FTK301_certificate (identity) is added to the 'Personal' that is used and verified by the PKI peer configured on FortiGate. This guarantees that upon reaching a secure resource, the appropriate policy is matched.
Related article: How to configure FortiClient to use FortiToken 300 for certificate authentication. |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.