Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
TJF
New Contributor

SSL VPN Certificate/PKI Authentication

Hi All,

 

We're attempting to setup a new SSL VPN where the only authentication requirements would either be a public/private key combination, or the use of an SSL certificate. I've read a good amount of documentation, but from what I've seen, it's only for two factor authentication. Also, this is using 5.2.1.

 

Is there a way to have a client authenticate once with the FortiGate and then use a public key to keep reconnecting without having to use the password again?

 

Or, can we just use an SSL certificate for authentication without the need to input a password?

 

Thank you for your time.

1 REPLY 1
Jeff_FTNT
Staff
Staff

Yes, you can do that with PKI user.

 

Create PKI user from CLI (CLI only) : config user peer/edit xx/set subject xx/end

Add peer user to user group , CLI:config user group/edit xx/... end, donot user "peer group".

Then use "user group " in SSLVPN policy.

 

The trick it "peer user " can only create it from CLI, then it will show up on GUI, so you may not find it,thanks.

 

Announcements

Select Forum Responses to become Knowledge Articles!

Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.

Labels
Top Kudoed Authors