12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

VPN Certificates<br />

CA Certificates<br />

Import<br />

Name<br />

Subject<br />

Delete icon<br />

View Certificate<br />

Detail icon<br />

Download icon<br />

Import a public OCSP certificate. See “Importing CA certificates” on<br />

page 376.<br />

The names of existing Remote (OCSP) certificates. The <strong>FortiGate</strong> unit<br />

assigns unique names (REMOTE_Cert_1, REMOTE_Cert_2,<br />

REMOTE_Cert_3, and so on) to the Remote (OCSP) certificates when<br />

they are imported.<br />

Information about the Remote (OCSP) certificate.<br />

Delete a Remote (OCSP) certificate from the <strong>FortiGate</strong> configuration.<br />

Display certificate details.<br />

Save a copy of the Remote (OCSP) certificate to a local <strong>com</strong>puter.<br />

Importing Remote (OCSP) certificates<br />

To import a Remote (OCSP) certificate, go to VPN > Certificates > Remote and<br />

select Import.<br />

Figure 246:Upload Remote Certificate<br />

Local PC<br />

Browse<br />

Use a local administrator’s PC to upload a public certificate. Enter<br />

the location, or select Browse to navigate to the location of the<br />

certificate.<br />

Browse to the location on the management <strong>com</strong>puter where the<br />

certificate has been saved, select the certificate, and then select<br />

OK.<br />

The system assigns a unique name to each Remote (OCSP) certificate. The<br />

names are numbered consecutively (REMOTE_Cert_1, REMOTE_Cert_2,<br />

REMOTE_Cert_3, and so on).<br />

CA Certificates<br />

When you apply for a signed personal (administrative) or group certificate to<br />

install on remote clients, you must obtain the corresponding root certificate and<br />

CRL from the issuing CA.<br />

When you receive the signed personal or group certificate, install the signed<br />

certificate on the remote client(s) according to the browser documentation. Install<br />

the corresponding root certificate and CRL from the issuing CA on the <strong>FortiGate</strong><br />

unit.<br />

Installed CA certificates are displayed in the CA Certificates list. You cannot<br />

delete the Fortinet_CA certificate. To view installed CA root certificates or import a<br />

CA root certificate, go to VPN > Certificates > CA Certificates. To view root<br />

certificate details, select the View Certificate Detail icon in the row that<br />

corresponds to the certificate.<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

01-30005-0203-20070830 375

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!