FortiGate
FortiGate Next Generation Firewall utilizes purpose-built security processors and threat intelligence security services from FortiGuard labs to deliver top-rated protection and high performance, including encrypted traffic.
Shashwati
Staff
Staff
Article Id 295903
Description This article describes that it is not possible to connect via SSL VPN when a Require Client Certificate is enabled.
Scope FortiGate v6.X and v7.X.
Solution
  1. After enabling Require Client Certificate for SSL VPN settings:

 

1.PNG

 

  1. Verify that the User CA certificate is installed on the Firewall. It will be used to authenticate the SSL VPN user's certificate. Go to System -> Certificates -> Select Import -> CA Certificate and select the certificate file.

 

2.PNG

 

  1. The CA certificate now appears in the list of Remote CA Certificates. In this example, it is called CA_Cert_1.

 

3.PNG

 

  1. A user certificate must be installed on the user’s PC. When the user tries to authenticate, the user certificate is checked against the CA certificate to verify that they match.

 

Related article:

SSL VPN with certificate authentication

Contributors