Fortinet white logo
Fortinet white logo

SD-WAN Deployment for MSSPs

Certificate Templates

Certificate Templates

Tooltip

API folder: Foundation / Certificate Templates

The Certificate Templates are used to issue certificates for the IPsec authentication.

To create the Certificate Templates interactively:
  1. Go to Device Manager > Provisioning Templates. Under Certificate Templates, click Create New to create two templates named "Edge" and "Hub":

    Note

    The Certificate Name field (in our example is "Edge" or "Hub") is used for the name of the generated certificate on the FortiGate. Therefore, this name must correspond to the name used in the IPsec configuration. In our case, the IPsec configuration is generated by the Jinja Orchestrator and uses the above names by default.

  2. Set Type to Local to use the Certificate Authority (CA) built into FortiManager:

    Note

    External CA is also supported. This can be a third-party product or FortiAuthenticator. The latter is worth considering, and it can run inside FMG as a Management Extension application (MEA)!

  3. Configure the required certificate parameters and save the templates.

Certificate Templates

Certificate Templates

Tooltip

API folder: Foundation / Certificate Templates

The Certificate Templates are used to issue certificates for the IPsec authentication.

To create the Certificate Templates interactively:
  1. Go to Device Manager > Provisioning Templates. Under Certificate Templates, click Create New to create two templates named "Edge" and "Hub":

    Note

    The Certificate Name field (in our example is "Edge" or "Hub") is used for the name of the generated certificate on the FortiGate. Therefore, this name must correspond to the name used in the IPsec configuration. In our case, the IPsec configuration is generated by the Jinja Orchestrator and uses the above names by default.

  2. Set Type to Local to use the Certificate Authority (CA) built into FortiManager:

    Note

    External CA is also supported. This can be a third-party product or FortiAuthenticator. The latter is worth considering, and it can run inside FMG as a Management Extension application (MEA)!

  3. Configure the required certificate parameters and save the templates.