12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

VPN Certificates<br />

Local Certificates<br />

Importing a signed server certificate<br />

Your CA will provide you with a signed server certificate to install on the <strong>FortiGate</strong><br />

unit. When you receive the signed certificate from the CA, save the certificate on a<br />

<strong>com</strong>puter that has management access to the <strong>FortiGate</strong> unit.<br />

To install the signed server certificate, go to VPN > Certificates > Local<br />

Certificates and select Import. Install the signed certificate through the Upload<br />

Local Certificate dialog box at the top of the page. The certificate file can be in<br />

either PEM or DER format. The other dialog boxes are for importing previously<br />

exported certificates and private keys.<br />

Figure 242:Upload Local Certificate<br />

Certificate File<br />

Browse<br />

Enter the full path to and file name of the signed server certificate.<br />

Alternatively, browse to the location on the management <strong>com</strong>puter<br />

where the certificate has been saved, select the certificate, and<br />

then select OK.<br />

Importing an exported server certificate and private key<br />

The server certificate and private key to import must have been exported<br />

previously as a single PKCS12 file through the execute vpn certificate<br />

key export CLI <strong>com</strong>mand. The file is associated with a password, which you<br />

will need to know in order to import the file. Before you begin, save a copy of the<br />

file on a <strong>com</strong>puter that has management access to the <strong>FortiGate</strong> unit. For more<br />

information, see the <strong>FortiGate</strong> Certificate Management User <strong>Guide</strong>.<br />

To import the PKCS12 file, go to VPN > Certificates > Local Certificates and<br />

select Import.<br />

Figure 243:Upload PKCS12 Certificate<br />

Certificate with key<br />

file<br />

Browse<br />

Password<br />

Enter the full path to and file name of the previously exported<br />

PKCS12 file.<br />

Alternatively, browse to the location on the management <strong>com</strong>puter<br />

where the PKCS12 file has been saved, select the file, and then<br />

select OK.<br />

Type the password needed to upload the PKCS12 file.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 373

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!