Hello I am using a fortigate VPN. I post pages in the user's panel, via VPN-Portals. The problem is that one of the pages requires a user certificate and when the user wants to enter the site, the message "no certificate" appears. The user has this certificate imported into the browser and when he does not use VPN, the website works properly. The problem arises when I log into the VPN and want to use the bookmark. The certificate has the .p12 extension. Each user of this website has their own certificate. How can I fix the problem for the website to work via VPN? Should I import the certificate somewhere or somehow force the VPN to read certificates from the browser? Thank you for your help.
haven't tried this exact scenario with fortigate sslvpn webportal but knowing how client certificates work this isn't possible.
there has to be an end to end ssl sesion between the client and the server. if you put something like a reverse proxy or sslvpn webportal in between the client certificate will be available there at the front but not behind it.
client ssl certificates are used to proof who you are, so with a sslvpn before the website i would say the client certificate wouldnt be needed, but that is something for the customer to decide.
Have you considered switching to the Tunnel from Web mode?
No, could you say more?
That sounds like if you route all traffic through the vpn once it is up and running and your Gateway does some proxying. If it is a FGT it might have some UTM like deep or certificate inspection enabled on the matched policy.
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1738 | |
1108 | |
752 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.