FortiGate SSL VPN (With AD/LDAPS Authentication)

Поделиться
HTML-код
  • Опубликовано: 5 янв 2021
  • How to configure FortiGate Remote Access SSL-VPN. Using Active Directory authentication, (with LDAPS).Using the FortiClient
    www.petenetlive.com/kb/articl...
    CA Export Command: certutil -ca.cert certificate-name.cer
  • ХоббиХобби

Комментарии • 15

  • @ddubeya
    @ddubeya 2 года назад

    This worked perfectly for me. Thank you for the detailed direction.

  • @rabfiz7025
    @rabfiz7025 2 года назад

    Awesome video thank you! just wanted to mention that I was able to login to the SSL VPN portal but not to the LAN resources. Enabling NAT in the firewall policy fixed that issue.

  • @mariyatelitsina7008
    @mariyatelitsina7008 3 года назад

    thank you for such a detailed instuction.

  • @everlastinggobstopper6879
    @everlastinggobstopper6879 2 года назад

    very nice instructions..i used it verbatim

  • @tonymarms8908
    @tonymarms8908 3 года назад

    hi may i know what fw version is running in your test environment? I can't import CA certificate having error "Incorrect certificate file format for CA/LOCAL/CRL/REMOTE cert. 😢

  • @Sabs761010
    @Sabs761010 2 месяца назад +1

    Hi, i have a question , how to setup the SSL VPN in order the users get connect to the VPN throught fqdn instead ip?

  • @romansubbotin5175
    @romansubbotin5175 3 года назад

    Dear PeteNet, m.b. you know how to configure inactivity shutdown after 10 min inactivity? Thank You.

  • @azharifahmi3903
    @azharifahmi3903 2 года назад

    Hi, how I get file self-sign in Server-Certificate?

  • @powerofgames6637
    @powerofgames6637 2 года назад

    how i can make the vpn connected only through domain laptop only , not personal laptop or phones

  • @Traumatree
    @Traumatree Год назад +1

    The sound is really bad, but the most important information of the ldap server configuration on the Fortigate is to use the FQDN name of your LDAP server and not its IP address, as the certificate doesn't have the IP but the FQDN.

    • @Sabs761010
      @Sabs761010 2 месяца назад

      Hi, i have a question , how to setup the SSL VPN in order the users get connect to the VPN throught fqdn instead ip?

  • @romansubbotin5175
    @romansubbotin5175 3 года назад

    Hi thare, how can i finde tutorial where you prepared Windows server roles: Certification autority and NPS? Thank you!

    • @dont_test_me_bish
      @dont_test_me_bish 3 года назад

      You won't need all that unless using RADIUS. LDAP/S works direct from firewall to the DC.

    • @gercast82
      @gercast82 2 года назад

      @@dont_test_me_bish You need a CA to LDAP over SSL (LDAPS) to work. In the other hand, LDAP doesn't need a CA.

    • @dont_test_me_bish
      @dont_test_me_bish 2 года назад +1

      @@gercast82 Not if you point the client to the ssl port(636) and pre-accept the cert or turn off cert verification on the client. Who knows when MS CA is gonna crap the bed? This still keeps cleartext creds off the wire