Created on 
    
	
		
		
		03-17-2025
	
		
		03:52 AM
	
	
	
	
	
	
	
	
	
	
	
	
	
	
  Edited on 
    
	
		
		
		03-17-2025
	
		
		03:56 AM
	
	
	
	
	
	
	
	
	
	
	
	
	
	
 By  
				
		
		
			Anthony_E
		
		
		
		
		
		
		
		
	
			 
		
| Description | This article describes how to configure the IPSec tunnel with the certificate-based authentication. | 
| Scope | FortiGate. | 
| Solution | 
 When the certificate-based authentication is used for IKE, the default FortiGate built-in certificate can be used. 
 
 In the above configuration, the entity certificate is used as Fortinet_Factory and the CA certificate as built-in Fortinet_Sub_CA. 
 Since the keys and dependencies for these built-in certificates are available with the firewall, there is no need to import additional key files here. 
 
 Once the configuration is done, phase1 status will be up. 
 LAB # diagnose vpn ike gateway list name S2S 
 vd: root/0 
   id/spi: 4 7f307ee05619b343/e0329706744c1643 
 If a third-party CA-signed certificate needs to be used, import the key file as the cert file. 
 It is also necessary to import the CA certificate on both the VPN endpoints.  | 
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.