Hi All,
We're attempting to setup a new SSL VPN where the only authentication requirements would either be a public/private key combination, or the use of an SSL certificate. I've read a good amount of documentation, but from what I've seen, it's only for two factor authentication. Also, this is using 5.2.1.
Is there a way to have a client authenticate once with the FortiGate and then use a public key to keep reconnecting without having to use the password again?
Or, can we just use an SSL certificate for authentication without the need to input a password?
Thank you for your time.
Yes, you can do that with PKI user.
Create PKI user from CLI (CLI only) : config user peer/edit xx/set subject xx/end
Add peer user to user group , CLI:config user group/edit xx/... end, donot user "peer group".
Then use "user group " in SSLVPN policy.
The trick it "peer user " can only create it from CLI, then it will show up on GUI, so you may not find it,thanks.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1741 | |
1109 | |
755 | |
447 | |
240 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.