Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Zeihold_von_SSL
New Contributor

SSL-VPN authentication mechanism

Hello everybody, I have a question regarding ssl-vpn authentication. Today we use username/password for authenticating our ssl-vpn users. This is okay, but I want to add a little bit more security to it. About six months ago we implemented a root and a enterprise intermediate CA to our active directory so our clients already have client certificates enrolled. So I wanted to use that certificates to authenticate our users. The thing is, that I want to keep username/password authentication as a fallback mechanism (for example when a user is connecting from his private computer). I know that this is possible with our Cisco ASA, but is this also possible with a Fortigate?

Regards Rene ---

[size="1"]FCNSA.v5, FCNSP.v5, FCESP[/size]

Home: FWF60D FortiAP 220B Office: FWF60C, FWF60D, FGT110C, FGT200B, FortiManager, FortiAnalyzer, FortiAP 220B

Regards Rene --- [size="1"]FCNSA.v5, FCNSP.v5, FCESP[/size] Home: FWF60D FortiAP 220B Office: FWF60C, FWF60D, FGT110C, FGT200B, FortiManager, FortiAnalyzer, FortiAP 220B
2 REPLIES 2
Anne
New Contributor III

Please check it with the TAC and update us as well. It will be good to have such a feature so that if the certificates expire, we are not panicking. Thanks Anne
Zeihold_von_SSL
New Contributor

Hi Anne, don' t get me wrong, but the last time I asked TAC for writing down a feature request (configure a custom NAS identifier (http://en.wikipedia.org/wiki/RADIUS -> attribute value pair 32) - support ticket 856701) they told me that I should contact sales (which was impossible due to a non functional email address). So I gave that to our partner (and I don' t know what happend then). So I don' t have much faith in TAC support any more (especially when it comes to feature requests). Kind Regards René

Regards Rene ---

[size="1"]FCNSA.v5, FCNSP.v5, FCESP[/size]

Home: FWF60D FortiAP 220B Office: FWF60C, FWF60D, FGT110C, FGT200B, FortiManager, FortiAnalyzer, FortiAP 220B

Regards Rene --- [size="1"]FCNSA.v5, FCNSP.v5, FCESP[/size] Home: FWF60D FortiAP 220B Office: FWF60C, FWF60D, FGT110C, FGT200B, FortiManager, FortiAnalyzer, FortiAP 220B
Labels
Top Kudoed Authors