Hiho,
I'm planning on activating SSL Deep Inspection via our FMG. So I got a SubCA Certificate from our internal CA for each of our FGTs the usuall way (generate CSR on FGT and then sign it with the CA and import the certificate). So far everything went wthout any problem. Every FGT now has a SSL Certificate for https and and a SubCA Certifcate from our CA on it.
Now I need to map this inside FMG to be able to configure the cert to be used for SSL Deep Inspection and this is where the problems start:
On my FGTs the SubCA can only be imported as CA Certificate (which is correct though) but gets importet into external CA Certificates. And for some reason external Certificates installed on the FGT are not available in FMG :\
I can only choose the SSL Cert which is installed as local certificate on the FGT. in FMG.
Is there any solution to make external certs available in FMG or have the FGT install SubCA to local CA instead of remote?
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Nominating a forum post submits a request to create a new Knowledge Article based on the forum post topic. Please ensure your nomination includes a solution within the reply.
Hm maybe I found out myself. One FGT allowed me to install a subca as local certificate which then should be available in FMG. So the other FGT should do aswell. Will check on this tomorrow...
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
yes obivously that's the solution.
- create a CSR on your FortiGate
- use your CA to create a certificate (Type: SubCA) from that CSR
- import the certificate - not as a CA (even though it is one) but as local certificate
then you see it in FMG and can do mapping. The mapping can then be used in a SSL Inspection PRofile
--
"It is a mistake to think you can solve any major problems just with potatoes." - Douglas Adams
Select Forum Responses to become Knowledge Articles!
Select the “Nominate to Knowledge Base” button to recommend a forum post to become a knowledge article.
User | Count |
---|---|
1545 | |
1030 | |
749 | |
443 | |
210 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2024 Fortinet, Inc. All Rights Reserved.