12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

PKI authentication<br />

User<br />

Protocol<br />

Certificate<br />

Select a secure LDAP protocol to use for authentication. Depending on<br />

your selection, the value in Server Port will change to the default port for<br />

the selected protocol.<br />

Select a certificate to use for authentication from the drop-down list. The<br />

certificate list <strong>com</strong>es from CA certificates at VPN > Certificates ><br />

CA Certificates.<br />

Figure 258:LDAP server Distinguished Name Query tree<br />

PKI authentication<br />

Public Key Infrastructure (PKI) authentication utilizes a certificate authentication<br />

library that takes a list of ‘peers’, ‘peer’ groups, and/or user groups and returns<br />

authentication ‘successful’ or ‘denied’ notifications. Users only need a valid<br />

certificate for successful authentication - no username or password are necessary.<br />

For more information about certificate authentication, see the <strong>FortiGate</strong> Certificate<br />

Management User <strong>Guide</strong>. For information about the detailed PKI configuration<br />

settings only available through the CLI, see the <strong>FortiGate</strong> CLI Reference.<br />

Go to User > PKI to configure PKI users.<br />

Figure 259:User > PKI user list<br />

Create New<br />

User Name<br />

Subject<br />

Issuer<br />

Delete icon<br />

Edit icon<br />

Add a new PKI user.<br />

The name of the PKI user.<br />

The text string that appears in the subject field of the certificate of<br />

the authenticating user.<br />

The CA certificate that is used to authenticate this user.<br />

Delete this PKI user.<br />

Edit this PKI user.<br />

Note: The following fields in the PKI User List correspond to the noted fields in the PKI<br />

User dialog:<br />

User Name: Name<br />

Subject: Subject<br />

CA: Issuer (CA certificate)<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

384 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!