Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hi, I was wondering did you have to do anything "special" to get this to work, I am trying to get this to work, but am having an access denied error message on my SSL-VPN clients.
You mentioned you use the CA Certificate, so how did you set this up for the client computers? Did you follow some documentation you can point me to?.
Thanks in Advance
The issue with this was eventually tied up with the LDAP authentication and not the certificate.
I had "CA" under the Name Identifier. It was suppose to be "SAMACCOUNTNAME".
Per your question, I'm afraid I'm still figuring out how it works.
Once I do I'll be sure to blog it.
I have managed to get this to work, it took some reading across multiple forums.
I followed this one to create the self signing certificates
The trick was that when building the certificate, I had to put in the section of the FQDN the SAME distinguished name configuration that had been used when setting up the LDAP interface, so in my case the FQDN had the entries of dc=xxxxx,dc=local, which matched the Distinguished Name in the LDAP configuration.
I then followed the remaining instructions above and imported the certificate as a CA Certificate and the P12 file as a user certificate on the device, but you have to import it when logged on as the USER who wants to remotely connect. Then configured the Forticlient to use this certificate and it worked,
I have just one certificate that I will use for those staff that need remote access, but you could create and load a remote certificate for each user, but didn't see a need.
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1713 | |
1093 | |
752 | |
447 | |
231 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.