Certificates
To use a certificate with FortiLink:
-
Upload the CA certificate to the FortiGate device. For example:
-
# execute vpn certificate ca import auto <CA_server> [identifier] [source_ip] [fingerprint]
-
# execute vpn certificate ca import bundle <filename> <tftp_IP>
-
# execute vpn certificate ca import tftp <filename> <server_address>
-
# execute vpn certificate ems_ca import tftp <filename> <server_address>
-
-
Set the tunnel mode on the FortiGate device to
moderate
orcompatible
:config switch-controller system
set tunnel-mode {moderate | compatible)
end
Use the
set tunnel-mode moderate
setting when you need peer verification but not host verification.