Disable Hardware Cryptographic Acceleration - Digi IX14 User Manual

Hide thumbs Also See for IX14:
Table of Contents

Advertisement

Virtual Private Networks (VPN)
(config network scep_client Fortinet_SCEP_client)> distinguished_name
l value
(config network scep_client Fortinet_SCEP_client)>
e. Set the Organization:
(config network scep_client Fortinet_SCEP_client)> distinguished_name
o value
(config network scep_client Fortinet_SCEP_client)>
f. Set the Organizational Unit:
(config network scep_client Fortinet_SCEP_client)> distinguished_name
ou value
(config network scep_client Fortinet_SCEP_client)>
g. Set the Common Name:
(config network scep_client Fortinet_SCEP_client)> distinguished_name
cn value
(config network scep_client Fortinet_SCEP_client)>
8. Set the number of days that the certificate enrollment can be renewed, prior to the request
expiring. This value must match the setting of the Allow renewal x days before the certified
is expired option on the Fortinet server.
(config network scep_client Fortinet_SCEP_client)> renewable_time integer
(config network scep_client Fortinet_SCEP_client)>
9. (Optional) Set the filename of the Certificate Revocation List (CRL) from the CA.
The CRL is stored on the IX14 device in the /etc/config/scep_client/client_name directory.
(config network scep_client Fortinet_SCEP_client)> crl_name name
(config network scep_client Fortinet_SCEP_client)>
10. Save the configuration and apply the change:
(config network scep_client Fortinet_SCEP_client)> save
Configuration saved.
>
11. Type exit to exit the Admin CLI.
Depending on your device configuration, you may be presented with an Access selection
menu. Type quit to disconnect from the device.

Disable hardware cryptographic acceleration

If you are experiencing problems when using IPSEC, such as the kernel crashing or unexpected
package loss, disabling hardware cryptographic acceleration may correct the problem.
  WebUI
IX14 User Guide
IPsec
579

Advertisement

Table of Contents
loading

Table of Contents