Hello,
I need to create VPN IPsec S2S tunnel with certificate authentication.
What i need in Subject and Key Usage/Enhanced Key Usage in that certificate?
For now i use certificate with address IP in Common Name and Client/Server Authentication (Enhanced Key Usage) on each sites.
Thats is ok?
That should be fine, but a name in the subject field would be ideal.
Ken
PCNSE
NSE
StrongSwan
Name of what? UTM hostname? In VPN config I can't enter domain name. I can use only IP address.
If your talking about the CN field; it could be something as simple as a username, hostname, email, rfc822name, etc....
PCNSE
NSE
StrongSwan
I think he is referring to the user peer configuration:
Enter the peer certificate common name type: FQDN — Fully-qualified domain name. email — The user’s email address. ipv4 — The user’s IP address (IPv4). ipv6 — The user’s IP address (IPv6). string — Any other piece of information.
follow the ftnt example
PCNSE
NSE
StrongSwan
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1747 | |
1114 | |
760 | |
447 | |
241 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.