Fortinet white logo
Fortinet white logo

Examples

Configuring a gateway on the FortiPAM server

Configuring a gateway on the FortiPAM server

To configuring a gateway on the FortiPAM server:
  1. Go to Secrets > Gateway.
  2. In the Gateways list, select +Create.

    The New Gateway window opens.

  3. In Name, enter a name for the gateway.
  4. Ensure that the Status is enabled.
  5. Ensure that Type is Forward.
  6. In Address, enter the IP address of the forward proxy.

    This was set up on port1 in Configuring forward gateway on FortiGate.

  7. In Port, enter the gateway port number.

    In this example, it is 8443.

    This was set up in Configuring a gateway on the FortiPAM server.

  8. Ensure that the SSL Max Version is TLS 1.3 (default).
  9. Ensure that the TCP Forwarding Path is tcp (default). This tells the gateway how to internally process the request from FortiPAM.
  10. Optionally, enter a description.
  11. Click Submit.

Client Certificate is required only when client-cert is enabled in Configuring forward gateway on FortiGate.

CA Certificate is the CA for the FortiGate certificate configured in Configuring forward gateway on FortiGate (ssl-certificate).

If it is not configured, FortiPAM server does not check the FortiGate certificate during the TLS handshake.

Configuring a gateway on the FortiPAM server

Configuring a gateway on the FortiPAM server

To configuring a gateway on the FortiPAM server:
  1. Go to Secrets > Gateway.
  2. In the Gateways list, select +Create.

    The New Gateway window opens.

  3. In Name, enter a name for the gateway.
  4. Ensure that the Status is enabled.
  5. Ensure that Type is Forward.
  6. In Address, enter the IP address of the forward proxy.

    This was set up on port1 in Configuring forward gateway on FortiGate.

  7. In Port, enter the gateway port number.

    In this example, it is 8443.

    This was set up in Configuring a gateway on the FortiPAM server.

  8. Ensure that the SSL Max Version is TLS 1.3 (default).
  9. Ensure that the TCP Forwarding Path is tcp (default). This tells the gateway how to internally process the request from FortiPAM.
  10. Optionally, enter a description.
  11. Click Submit.

Client Certificate is required only when client-cert is enabled in Configuring forward gateway on FortiGate.

CA Certificate is the CA for the FortiGate certificate configured in Configuring forward gateway on FortiGate (ssl-certificate).

If it is not configured, FortiPAM server does not check the FortiGate certificate during the TLS handshake.