278
01-28006-0014-20041105
Fortinet Inc.
Certificates
VPN
3
Select Import.
4
Browse to the location on the local PC where the certificate has been saved and
select the certificate.
5
Select OK.
Figure 142:Importing a CA certificate
To install a CA’s root certificate
1
After you download the root certificate of the CA, save the certificate on a PC that has
local access to the FortiWiFi unit.
2
On the FortiWiFi unit, go to
VPN > Certificates > CA Certificates
.
3
Select Import.
4
Browse to the location on the local PC where the certificate has been saved and
select the certificate.
5
Select OK.
The system assigns a unique name to each CA certificate. The names are numbered
consecutively (CA_Cert_1, CA_Cert_2, CA_Cert_3, and so on).
Enabling VPN access for specific certificate holders
When a VPN peer is configured to authenticate using digital certificates, it sends the
Distinguished Name (DN) on its certificate to the remote peer. This DN can be used to
deny VPN access. For example, a FortiWiFi unit can be configured to deny
connections to all remote peers except the one having the specified DN.
If the FortiWiFi unit participates in a gateway-to-gateway configuration and you want
both peers to accept reciprocal connections, you must specify the DN of the FortiWiFi
unit when you define the phase 1 parameters.
Note:
Consider backing up the certificate. The file is saved in as a password protected PKCS12
(Public Key Cryptography Standard 12) file. You can use the backup if you need to restore the
original. For more information, see
“Backing up and Restoring” on page 122
.
Summary of Contents for Fortiwifi fortiwifi-60
Page 42: ...42 01 28006 0014 20041105 Fortinet Inc Changing the FortiWiFi firmware System status...
Page 78: ...78 01 28006 0014 20041105 Fortinet Inc Wireless MAC Filter System wireless...
Page 86: ...86 01 28006 0014 20041105 Fortinet Inc Dynamic IP System DHCP...
Page 120: ...120 01 28006 0014 20041105 Fortinet Inc Access profiles System administration...
Page 238: ...238 01 28006 0014 20041105 Fortinet Inc Protection profile Firewall...
Page 250: ...250 01 28006 0014 20041105 Fortinet Inc CLI configuration Users and authentication...
Page 326: ...326 01 28006 0014 20041105 Fortinet Inc CLI configuration Antivirus...
Page 372: ...372 01 28006 0014 20041105 Fortinet Inc CLI configuration Log Report...
Page 386: ...386 01 28006 0014 20041105 Fortinet Inc Glossary...