Man can someone please toss me a bone here, i been struggling for weeks to get cert auth working.
I've tried both SSL & IPSEC/XAUTH to get it to work...
Im using machine certs, my environment has a ms ca, currently use 802.1x auth everywhere else just fine. cant tell how to validate my cert setup. TAC states to check web auth with cert? not sure how to get the sslvpn portal to accept only a cert to test??
config user peer edit "PKI01" set ca "CA_Cert_1" set two-factor enable set passwd ENC itPfr+C/
***not sure why a password is used here??? is this even valid? All guide state to do so but dont state where password is even used.***
Within EMS i can configure the FC to use machine certs,
On SSL client gets to 48% and fails =
Credential or SSLVPN configuration is wrong. (-7200)
IPSEC option just hangs connecting, fairly sure my settings are correct. I've had TAC on this numerous times, i'm constantly pushed into some 'oh this is a bug will be fixed soon' but this has been an issue for months now.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1747 | |
1114 | |
761 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.