Virtual Private Networks (VPN)
IPsec
IX14 User Guide
575
Example: SCEP client configuration with Fortinet SCEP server
In this example configuration, we will configure the IX14 device as a SCEP client that will connect to a
Fortinet SCEP server.
Fortinet configuration
On the Fortinet server:
1. Enable ports for SCEP services:
a. From the menu, select
Network
>
Interfaces
.
b. Select the appopriate port and click
Edit
.
c. For
Access Rights
>
Services
, enable the following services:
n
HTTPS
>
SCEP
n
HTTPS
>
CRL Downloads
n
HTTP
>
SCEP
n
HTTP
>
CRL Downloads
d. The remaining fields can be left at their defaults or changed as appropriate.
e. Click
OK
.
2. Create a Certificate Authority (CA):
a. From the menu, click
Certificate Authorities
>
Local CAs
.
b. Click
Create New
.
c. Type a
Certificate ID
for the CA, for example,
fortinet_example_ca
.
d. Complete the
Subject Information
fields.
e. The remaining fields can be left at their defaults or changed as appropriate.
f. Click
OK
.
3. Edit SCEP settings:
a. From the menu, click
SCEP
>
General
.
b. Click
Enable SCEP
if it is not enabled.
c. For
Default enrollment password
, enter a password. The password entered here must
correspond to the challenge password configured for the SCEP client on the IX14 device.
d. The remaining fields can be left at their defaults or changed as appropriate.
e. Click
OK
.
4. Create an
Enrollment Request
:
a. From the menu, click
SCEP
>
Enrollment Requests
.
b. Click
Create New
.
c. For
Automatic request type
, select
Wildcard
.
d. For
Certificate authority
, select the CA created in step 1, above.
e. Complete the
Subject Information
fields. The Distinguished Name (DN) attributes entered
here must correspond to the Distinguished Name attributes configured for the SCEP client
on the IX14 device.
f. For
Renewal
>
Allow renewal
x
days before the certified is expired
, type the number of
days that the certificate enrollment can be renewed, prior to the request expiring. The
Renewable Time
setting on the IX14 device must match the setting of this parameter.
Содержание IX14
Страница 1: ...IX14 User Guide Firmware version 22 2 ...
Страница 45: ...Configuration and management Exit the command line interface IX14 User Guide 45 Type q or quit to exit ...
Страница 515: ...Monitoring This chapter contains the following topics intelliFlow 516 Configure NetFlow Probe 523 IX14 User Guide 515 ...
Страница 756: ...Routing Virtual Router Redundancy Protocol VRRP IX14 User Guide 756 ...
Страница 803: ...Command line interface Command line reference IX14 User Guide 803 Parameters None ...
Страница 812: ...Command line interface Command line reference IX14 User Guide 812 reboot Reboot the system Parameters None ...