Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
rajpaalsinha
New Contributor

Can I secure SSL VPN with a wildcard cert, if SSL VPN is IP based?

I am trying to put a cert on the SSL VPN. All I have access to is wildcard certs. I have already tried and failed, and now I am wondering if I can or if I am doing it wrong.

router login 192.168.l.l
3 REPLIES 3
AEK
SuperUser
SuperUser

Yes you can, but you need to access it via FQDN (e.g.: ssl.mydomain.com), not IP address, otherwise the cert is useless.

AEK
AEK
Hassan97wsh
Staff
Staff

The IP address will not match the certificate wildcard subject name or alternative subject name. The wildcard certificate cannot be used to authenticate the server by its IP address.

Hassan
TAC Engineer
jiahoong112
Staff
Staff

the wildcard certificate will only apply if the method you are connecting to the sslvpn is fqdn based. in this case, you'll have to bind your public ip with fqdn or use FortiDDNS: https://docs.fortinet.com/document/fortigate/7.6.2/administration-guide/685361/ddns 

**If you come across a resolution, kindly show your appreciation by liking and accepting it, ensuring its accessibility for others**
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors