12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Administrators<br />

System Administrators<br />

Configuring PKI certificate authentication for administrators<br />

Public Key Infrastructure (PKI) authentication utilizes a certificate authentication<br />

library that takes a list of ‘peers’, ‘peer’ groups, and/or user groups and returns<br />

authentication ‘successful’ or ‘denied’ notifications. Users only need a valid<br />

certificate for successful authentication - no username or password are necessary.<br />

If you want to use PKI authentication for an administrator, you must configure the<br />

authentication before you create the administrator accounts. To do this you need<br />

to:<br />

• create a PKI user group<br />

The following procedures assume that there is a RADIUS server on your network<br />

populated with the names and passwords of your administrators. For information<br />

on how to set up a RADIUS server, see the documentation for your RADIUS<br />

server.<br />

Go to User > PKI to configure PKI users.<br />

Figure 87: User > PKI user list<br />

Create New<br />

User Name<br />

Subject<br />

Issuer<br />

Delete icon<br />

Edit icon<br />

Add a new PKI user.<br />

The name of the PKI user.<br />

The text string that appears in the subject field of the certificate of<br />

the authenticating user.<br />

The CA certificate that is used to authenticate this user.<br />

Delete this PKI user.<br />

Edit this PKI user.<br />

Note: The following fields in the PKI User List correspond to the noted fields in the PKI<br />

User dialog:<br />

User Name: Name<br />

Subject: Subject<br />

CA: Issuer (CA certificate)<br />

To configure the <strong>FortiGate</strong> unit to access the RADIUS server<br />

1 Go to User > RADIUS.<br />

2 Select Create New.<br />

3 Enter the following information:<br />

Name<br />

A name for the RADIUS server. You use this name when you create the<br />

user group.<br />

Server Name/IP The domain name or IP address of the RADIUS server.<br />

Server Secret The RADIUS server secret. The RADIUS server administrator<br />

can provide this information.<br />

4 Select OK.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

164 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!