Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Daniyal007
New Contributor II

Fortigate Web Gui Certificate

Hi there,

I am accessing my FortiGate web GUI using a public IP address.

My question is, whenever I access the web GUI using the domain name, it does not show any error regarding an unsecured connection. However, whenever I try to access it using the IP address, it shows an unsecured connection error.

I want the FortiGate to only be accessible via the domain name with a secured, encrypted connection, and not via the IP address

1 Solution
ozkanaltas

Hello @Daniyal007 ,

 

If you can add the IP address of FortiGate to the San area. You will not see a warning when you connect with the IP address.

 

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW

View solution in original post

If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
9 REPLIES 9
ozkanaltas
Contributor III

Hello @Daniyal007

 

This is normal behavior. If your fqdn and certificate san or cn area are matched this warning disappears. 

 

Probably your certificate san or cn area does not include your IP address. Because of that, you see a warning if you connect with an IP address instead of fqdn.

 

There is no option for just connecting with fqdn on Fortigate. You need to resume this way.

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
Daniyal007
New Contributor II

so i have to add CN as domain name and ip address as SAN right?

ozkanaltas

Hello @Daniyal007 ,

 

If you can add the IP address of FortiGate to the San area. You will not see a warning when you connect with the IP address.

 

 

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
Daniyal007

my main focus is not to get warning when i access fortigate.

so according to your recommendation i have to add domain name in CN and ip address in SAN . thats how i dont get waring even when i access with domain or ip Right? 

pminarik

Make sure both are in the SAN.
Modern browsers validate addresses against SAN only, CN is ignored. (It used to be used as a backup attribute to check if a SAN doesn't exist in the cert, but that should no longer be the case for any major browser, AFAIK(

[ corrections always welcome ]
Daniyal007

ok so if i have 50 sites means 50 firewall deployed so i have to buy 50 certificates with san entries included or is their any way to add 50 site ip address in san against one domain??

ozkanaltas

Hi @Daniyal007 ,

 

As I know, you can add all domain addresses to the SAN area in one certificate. You don't need to buy a certificate for every domain name.

 

PS.

 

I found a document about the SAN certificate. I think good information includes about san.

 

https://www.thawte.com/resources/pdfs/Thawte_Multiuse_SSL_WP.pdf

If you have found a solution, please like and accept it to make it easily accessible to others.
NSE 4-5-6-7 OT Sec - ENT FW
If you have found a solution, please like and accept it to make it easily accessible to others.NSE 4-5-6-7 OT Sec - ENT FW
pminarik
Staff
Staff

The validity of the certificate is evaluated based on whether the website address in the address bar matches the identity claimed in the certificate (in "subject alternative name" (SAN) attribute), among other things.

Your description is a strong indication that the current certificate has the domain name included in the SAN, but not the IP. 

[ corrections always welcome ]
Labels
Top Kudoed Authors