QuestionQ13

Authentication

Refer to the exhibits, which show debug output and SSL VPN configuration information.

Question Image

Question Image

Question Image

An SSL VPN is configured on FortiGate. To improve security, the administrator enabled Required Client Certificate in the SSL VPN settings. However, authentication fails when a user tries to connect.

Which configuration change is required to resolve the issue and allow the user to connect?

  • A Import the CA that signed the user certificate to FortiGate.
  • B Enable Redirect HTTP to SSL-VPN on the SSL VPN configuration page.
  • C Import the CA that signed the SSL VPN Server Certificate to FortiGate.
  • D Set the user certificate as the Server Certificate on the SSL VPN configuration page.
Explanation

With Required Client Certificate enabled, FortiGate must validate the user’s client certificate against a CA it trusts. The certificate-validation output shows that the client certificate chain cannot be completed from the trust store or CA cache. Importing the CA certificate that signed the user certificate provides the required trust anchor. Fortinet: SSL VPN with certificate authentication

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!