Hi Everyone,
I need assistance with the following query:
"A customer wants to establish mutual TLS (two-way TLS) authentication between their collector and our supervisor. Is this possible?"
Thanks in advance!
Hi Arif,
I hope you are doing well.
Sure, let me find somebody to answer.
Regards,
Hi @beingarif,
I think, the closest you can get here is following this guide:
https://docs.fortinet.com/document/fortisiem/7.2.5/configuring-ca-certificates/226157
I have to admit, I did not read through this, because I have not seen this kind of requirement in our implementations yet.
The main question behind that is "how can we improve security in the setup". I think, you should first go through this document: https://docs.fortinet.com/document/fortisiem/7.2.5/hardening-guide/582961
That's a lot do refine before trying to refine MITM-scenarios between Collector and Cluster.
Best,
Christian
Thank you @Secusaurus !
We have implemented CA issued wildcard SSL Certificate in Supervisor, Worker and Collector and added host names in etc/hosts. Securing all to and fro communications with TLS yet not exposing servers by adding DNS record anywhere.
Welcome to your new Fortinet Community!
You'll find your previous forum posts under "Forums"
User | Count |
---|---|
72 | |
25 | |
15 | |
10 | |
10 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.