Fortinet white logo
Fortinet white logo

Examples

Configuring a gateway entry on FortiPAM server for secret launch (traffic plane)

Configuring a gateway entry on FortiPAM server for secret launch (traffic plane)

To configure a FortiPAM gateway entry on FortiPAM:
  1. Go to Network > Secret Gateway.
  2. From the Gateways List, select Create.

    The New Gateway window opens.

  3. Enter a name for the gateway.
  4. Ensure that the status is set to enable.
  5. In Type, select Reverse.
  6. In Address, enter the gateway IPv4 address.
  7. In Port, enter 7443.

    The Address and Port were configured in vip in Configuring traffic proxy on the gateway for forwarding secret launch (traffic plane).

  8. Ensure that Health Check is enabled and set to 60 seconds.

    The gateway status is displayed on the right.

  9. Optionally, enter a description.
  10. In Gateway ID, enter the gateway client certificate common name to create mapping between FortiPAM and the gateway.
  11. In Mode, select Reverse Gateway.
  12. In SSL Max Version, select TLS 1.3.
  13. In the Client Certificate dropdown, select the client certificate for mTLS.

    The Client Certificate is the current server certificate for secret launch.

    It is required only when client-cert is set to enable in access-proxy in Configuring traffic proxy on the gateway for forwarding secret launch (traffic plane).

    The certificate CA is configured on the gateway using the CLI commands as shown below or from Network > FortiPAM Server > Server CA:

     config authentication setting
      set user-cert-ca "CA_Cert_1"
     end			  
    
  14. Click Submit.

To configure a FortiGate gateway entry on FortiPAM:
  1. Go to Network > Secret Gateway.
  2. From the Gateway List, select Create.

    The New Gateway window opens.

  3. Enter a name for the gateway.
  4. Ensure that the status is set to Enable.
  5. From the Type dropdown, select Reverse.
  6. In Address, enter the gateway IPv4 address.
  7. In Port, enter 9443.

    The Gateway Address and Port were configured in ztna traffic-forward-proxy in Configuring traffic proxy on the gateway for forwarding secret launch (traffic plane).

  8. Ensure that Health Check is enabled and set to 60 seconds.
  9. Optionally, enter a description.
  10. In Gateway ID, enter the FortiGate reverse gateway common name.
  11. In Mode, select Reverse Gateway.
  12. In SSL Max Version, select TLS 1.3.
  13. In the Client Certificate dropdown, select the client certificate for mTLS.

    The Client Certificate is the current server certificate for secret launch.

    It is required only when client-cert is set to enable in traffic-forward-proxy in Configuring traffic proxy on the gateway for forwarding secret launch (traffic plane).

    The certificate CA is configured on the gateway using the CLI commands as shown below or from Network > FortiPAM Server > Server CA:

     config authentication setting
      set user-cert-ca "CA_Cert_1"
     end 	
  14. Click Submit.

Configuring a gateway entry on FortiPAM server for secret launch (traffic plane)

Configuring a gateway entry on FortiPAM server for secret launch (traffic plane)

To configure a FortiPAM gateway entry on FortiPAM:
  1. Go to Network > Secret Gateway.
  2. From the Gateways List, select Create.

    The New Gateway window opens.

  3. Enter a name for the gateway.
  4. Ensure that the status is set to enable.
  5. In Type, select Reverse.
  6. In Address, enter the gateway IPv4 address.
  7. In Port, enter 7443.

    The Address and Port were configured in vip in Configuring traffic proxy on the gateway for forwarding secret launch (traffic plane).

  8. Ensure that Health Check is enabled and set to 60 seconds.

    The gateway status is displayed on the right.

  9. Optionally, enter a description.
  10. In Gateway ID, enter the gateway client certificate common name to create mapping between FortiPAM and the gateway.
  11. In Mode, select Reverse Gateway.
  12. In SSL Max Version, select TLS 1.3.
  13. In the Client Certificate dropdown, select the client certificate for mTLS.

    The Client Certificate is the current server certificate for secret launch.

    It is required only when client-cert is set to enable in access-proxy in Configuring traffic proxy on the gateway for forwarding secret launch (traffic plane).

    The certificate CA is configured on the gateway using the CLI commands as shown below or from Network > FortiPAM Server > Server CA:

     config authentication setting
      set user-cert-ca "CA_Cert_1"
     end			  
    
  14. Click Submit.

To configure a FortiGate gateway entry on FortiPAM:
  1. Go to Network > Secret Gateway.
  2. From the Gateway List, select Create.

    The New Gateway window opens.

  3. Enter a name for the gateway.
  4. Ensure that the status is set to Enable.
  5. From the Type dropdown, select Reverse.
  6. In Address, enter the gateway IPv4 address.
  7. In Port, enter 9443.

    The Gateway Address and Port were configured in ztna traffic-forward-proxy in Configuring traffic proxy on the gateway for forwarding secret launch (traffic plane).

  8. Ensure that Health Check is enabled and set to 60 seconds.
  9. Optionally, enter a description.
  10. In Gateway ID, enter the FortiGate reverse gateway common name.
  11. In Mode, select Reverse Gateway.
  12. In SSL Max Version, select TLS 1.3.
  13. In the Client Certificate dropdown, select the client certificate for mTLS.

    The Client Certificate is the current server certificate for secret launch.

    It is required only when client-cert is set to enable in traffic-forward-proxy in Configuring traffic proxy on the gateway for forwarding secret launch (traffic plane).

    The certificate CA is configured on the gateway using the CLI commands as shown below or from Network > FortiPAM Server > Server CA:

     config authentication setting
      set user-cert-ca "CA_Cert_1"
     end 	
  14. Click Submit.