Hello everybody,
We distribute device scep certificates via intune over a PKI instance to authenticate our devices via LAN and WiFi via a RADIUS server. However, our Fortigate does not serve as the RADIUS server. We use a Cloud Radius server and also a cloud provider as PKI for the scep certificates.
Currently we use IPsec VPN via SAML login and pre shared key.
Is it possible to use the already distributed devices certificates for remote login of the IPsec VPN instead of the pre shared key? However, I would still like to use SAML for user authentication. Or does this make no sense at all?
Regards
fabs
Hello fabs,
Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible.
Thanks,
Hello fabs,
We are still looking for someone to help you.
We will come back to you ASAP.
Regards,
Hi fabs,
Did you already have a look at this document?:
Regards,
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1741 | |
1109 | |
753 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.