It all comes down to what the purpose of each certificate is, either the
built-in defaults or ones you generate and import. The CA SSL proxy
certificate is specifically meant for the FortiGate to act as a "CA
on-the-fly", and re-write the certificate...
To paraphrase terribly what I've seen come through our internal forums
over the last week, I finally found out that Auto-IPsec was designed in
situations where a FortiManager was *not* used to centrally push out
configuration changes concerning VPN s...
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.