Pre-shared key vs digital certificates | Administration Guide (2024)

A FortiGate can authenticate itself to remote peers or dialup clients using either a pre-shared key or a digital certificate.

Pre-shared key

Using a pre-shared key is less secure than using certificates, especially if it is used alone, without requiring peer IDs or extended authentication (XAuth). There also needs to be a secure way to distribute the pre-shared key to the peers.

If you use pre-shared key authentication alone, all remote peers and dialup clients must be configured with the same pre-shared key. Optionally, you can configure remote peers and dialup clients with unique pre-shared keys. On the FortiGate, these are configured in user accounts, not in the phase 1 settings.

The pre-shared key must contain at least six printable characters and should be known by network administrators. For optimum protection against currently known attacks, the key must consist of a minimum of 16 randomly chosen alphanumeric characters. The limit is 128 characters.

If you authenticate the FortiGate using a pre-shared key, you can require remote peers or dialup clients to authenticate using peer IDs, but not client certificates.

To authenticate the FortiGate using a pre-shared key:
  1. Go to VPN > IPsec Tunnels and create a new tunnel, or edit an existing one.
  2. Configure or edit the Network section as needed.
  3. Configure or edit the Authentication settings as follows:

    Method

    Pre-shared Key

    Pre-shared Key

    <string>

    IKE Version

    1 or 2

    Mode

    Aggressive or Main

    Peer Options

    Select an Accept Type and the corresponding peer. Options vary based on the Remote Gateway and Authentication Method settings in the Network section.

    Peer Options are only available in Aggressive mode.

  4. For the Phase 1 Proposal section, keep the default settings unless changes are needed to meet your requirements.
  5. Optionally, for authentication parameters for a dialup user group, define XAUTH parameters.
  6. Click OK.

Digital certificates

To authenticate the FortiGate using digital certificates, you must have the required certificates installed on the remote peer and on the FortiGate. The signed server certificate on one peer is validated by the presence of the root certificate installed on the other peer. If you use certificates to authenticate the FortiGate, you can also require the remote peers or dialup clients to authenticate using certificates. See Site-to-site VPN with digital certificate for a detailed example.

To authenticate the FortiGate using a digital certificate:
  1. Go to VPN > IPsec Tunnels and create a new tunnel, or edit an existing one.
  2. Configure or edit the Network section as needed.
  3. Configure or edit the Authentication settings as follows:

    Method

    Signature

    Certificate Name

    Select the certificate used to identify this FortiGate. If there are no imported certificates, use Fortinet_Factory.

    IKE Version

    1 or 2

    Mode

    Aggressive is recommended.

    Peer Options

    For Accept Type, select Peer certificate and select the peer and the CA certificate used to authenticate the peer. If the other end is using the Fortinet_Factory certificate, then use the Fortinet_CA certificate here.

  4. For the Phase 1 Proposal section, keep the default settings unless changes are needed to meet your requirements.
  5. Optionally, for authentication parameters for a dialup user group, define XAUTH parameters.
  6. Click OK.
Pre-shared key vs digital certificates | Administration Guide (2024)
Top Articles
The Top 3 Cryptos to Buy in April 2024
Less Than 10% of Stablecoin Transaction Volume Coming from Real Users: Report
Custom Screensaver On The Non-touch Kindle 4
Uhauldealer.com Login Page
855-392-7812
Tj Nails Victoria Tx
Jefferey Dahmer Autopsy Photos
Comcast Xfinity Outage in Kipton, Ohio
EY – все про компанію - Happy Monday
WK Kellogg Co (KLG) Dividends
Derpixon Kemono
Tamilblasters 2023
2021 Lexus IS for sale - Richardson, TX - craigslist
The Connecticut Daily Lottery Hub
“In my day, you were butch or you were femme”
Tracking Your Shipments with Maher Terminal
Sony E 18-200mm F3.5-6.3 OSS LE Review
Kürtçe Doğum Günü Sözleri
Niche Crime Rate
Uktulut Pier Ritual Site
1v1.LOL - Play Free Online | Spatial
Indiana Wesleyan Transcripts
Sizewise Stat Login
Fort Mccoy Fire Map
CVS Near Me | Columbus, NE
Team C Lakewood
Baja Boats For Sale On Craigslist
Boston Dynamics’ new humanoid moves like no robot you’ve ever seen
Home
Cookie Clicker Advanced Method Unblocked
Mythical Escapee Of Crete
Safeway Aciu
Albertville Memorial Funeral Home Obituaries
Lininii
Bfri Forum
Elanco Rebates.com 2022
What Time Does Walmart Auto Center Open
Craigslist Red Wing Mn
The 38 Best Restaurants in Montreal
October 31St Weather
The Complete Guide To The Infamous "imskirby Incident"
When His Eyes Opened Chapter 2048
062203010
Immobiliare di Felice| Appartamento | Appartamento in vendita Porto San
All-New Webkinz FAQ | WKN: Webkinz Newz
Best Conjuration Spell In Skyrim
Mynord
Studentvue Calexico
Conan Exiles Tiger Cub Best Food
Meet Robert Oppenheimer, the destroyer of worlds
Who Is Nina Yankovic? Daughter of Musician Weird Al Yankovic
Bloons Tower Defense 1 Unblocked
Latest Posts
Article information

Author: Francesca Jacobs Ret

Last Updated:

Views: 6694

Rating: 4.8 / 5 (68 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Francesca Jacobs Ret

Birthday: 1996-12-09

Address: Apt. 141 1406 Mitch Summit, New Teganshire, UT 82655-0699

Phone: +2296092334654

Job: Technology Architect

Hobby: Snowboarding, Scouting, Foreign language learning, Dowsing, Baton twirling, Sculpting, Cabaret

Introduction: My name is Francesca Jacobs Ret, I am a innocent, super, beautiful, charming, lucky, gentle, clever person who loves writing and wants to share my knowledge and understanding with you.