Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can I secure SSL VPN with a wildcard cert, if SSL VPN is IP based?
I am trying to put a cert on the SSL VPN. All I have access to is wildcard certs. I have already tried and failed, and now I am wondering if I can or if I am doing it wrong.
router login 192.168.l.l
Labels:
- Labels:
-
FortiGate
3 REPLIES 3
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes you can, but you need to access it via FQDN (e.g.: ssl.mydomain.com), not IP address, otherwise the cert is useless.
AEK
AEK
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The IP address will not match the certificate wildcard subject name or alternative subject name. The wildcard certificate cannot be used to authenticate the server by its IP address.
Hassan
TAC Engineer
TAC Engineer
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
the wildcard certificate will only apply if the method you are connecting to the sslvpn is fqdn based. in this case, you'll have to bind your public ip with fqdn or use FortiDDNS: https://docs.fortinet.com/document/fortigate/7.6.2/administration-guide/685361/ddns
**If you come across a resolution, kindly show your appreciation by liking and accepting it, ensuring its accessibility for others**
