Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
kzuk
New Contributor

IPsec Site2Site Certificate

Hello,

 

I need to create VPN IPsec S2S tunnel with certificate authentication.

 

What i need in Subject and Key Usage/Enhanced Key Usage in that certificate?

 

For now i use certificate with address IP in Common Name and Client/Server Authentication (Enhanced Key Usage) on each sites.

 

Thats is ok?

5 REPLIES 5
emnoc
Esteemed Contributor III

That should be fine, but  a name in the subject  field would be ideal.

 

Ken

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
kzuk
New Contributor

Name of what? UTM hostname? In VPN config I can't enter domain name. I can use only IP address.

emnoc
Esteemed Contributor III

If your talking about  the CN field;  it could be something as simple as a username, hostname, email, rfc822name, etc....

 

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
oheigl
Contributor II

I think he is referring to the user peer configuration:

Enter the peer certificate common name type: FQDN — Fully-qualified domain name. email — The user’s email address. ipv4 — The user’s IP address (IPv4). ipv6 — The user’s IP address (IPv6). string — Any other piece of information.

emnoc
Esteemed Contributor III

PCNSE NSE StrongSwan
Labels
Top Kudoed Authors