272
01-28006-0068-20041105
Fortinet Inc.
Enabling VPN access for specific certificate holders
VPN
3
Select Import.
4
Browse to the location on the local PC where the certificate has been saved and
select the certificate.
5
Select OK.
Figure 138:Importing a CA certificate
To install a CA’s root certificate
1
After you download the root certificate of the CA, save the certificate on a PC that has
local access to the FortiGate unit.
2
On the FortiGate unit, go to
VPN > Certificates > CA Certificates
.
3
Select Import.
4
Browse to the location on the local PC where the certificate has been saved and
select the certificate.
5
Select OK.
The system assigns a unique name to each CA certificate. The names are numbered
consecutively (CA_Cert_1, CA_Cert_2, CA_Cert_3, and so on).
Enabling VPN access for specific certificate holders
When a VPN peer is configured to authenticate using digital certificates, it sends the
Distinguished Name (DN) on its certificate to the remote peer. This DN can be used to
deny VPN access. For example, a FortiGate unit can be configured to deny
connections to all remote peers except the one having the specified DN.
If the FortiGate unit participates in a gateway-to-gateway configuration and you want
both peers to accept reciprocal connections, you must specify the DN of the FortiGate
unit when you define the phase 1 parameters.
To enable access for a specific certificate holder or a group of certificate
holders
Use this procedure to enhance access security if you are using digital certificates to
authenticate peers.
1
Go to
VPN > IPSEC > Phase 1
.
Note:
Consider backing up the certificate. The file is saved in as a password protected PKCS12
(Public Key Cryptography Standard 12) file. You can use the backup if you need to restore the
original. For more information, see
“Backing up and Restoring” on page 116
.
Summary of Contents for FortiGate FortiGate-100A
Page 24: ...24 01 28006 0068 20041105 Fortinet Inc FortiLog documentation Introduction...
Page 72: ...72 01 28006 0068 20041105 Fortinet Inc Transparent mode VLAN settings System network...
Page 80: ...80 01 28006 0068 20041105 Fortinet Inc DHCP IP MAC binding settings System DHCP...
Page 114: ...114 01 28006 0068 20041105 Fortinet Inc Access profile options System administration...
Page 232: ...232 01 28006 0068 20041105 Fortinet Inc CLI configuration Firewall...
Page 244: ...244 01 28006 0068 20041105 Fortinet Inc peergrp Users and authentication...
Page 320: ...320 01 28006 0068 20041105 Fortinet Inc service smtp Antivirus...
Page 366: ...366 01 28006 0068 20041105 Fortinet Inc syslogd setting Log Report...
Page 380: ...380 01 28006 0068 20041105 Fortinet Inc Glossary...
Page 388: ...388 01 28006 0068 20041105 Fortinet Inc Index...