Fortinet white logo
Fortinet white logo

FortiLink Guide

Certificates

Certificates

To use a certificate with FortiLink:
  1. Upload the CA certificate to the FortiGate device. For example:

    • # execute vpn certificate ca import auto <CA_server> [identifier] [source_ip] [fingerprint]

    • # execute vpn certificate ca import bundle <filename> <tftp_IP>

    • # execute vpn certificate ca import tftp <filename> <server_address>

    • # execute vpn certificate ems_ca import tftp <filename> <server_address>

  2. Set the tunnel mode on the FortiGate device to moderate or compatible:

    config switch-controller system

    set tunnel-mode {moderate | compatible)

    end

    Note

    Use the set tunnel-mode moderate setting when you need peer verification but not host verification.

Certificates

Certificates

To use a certificate with FortiLink:
  1. Upload the CA certificate to the FortiGate device. For example:

    • # execute vpn certificate ca import auto <CA_server> [identifier] [source_ip] [fingerprint]

    • # execute vpn certificate ca import bundle <filename> <tftp_IP>

    • # execute vpn certificate ca import tftp <filename> <server_address>

    • # execute vpn certificate ems_ca import tftp <filename> <server_address>

  2. Set the tunnel mode on the FortiGate device to moderate or compatible:

    config switch-controller system

    set tunnel-mode {moderate | compatible)

    end

    Note

    Use the set tunnel-mode moderate setting when you need peer verification but not host verification.