03.04.2013 Views

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

FortiGate dialup-client<br />

configurations<br />

FortiOS Handbook<br />

This section explains how to set up a FortiGate dialup-client IPsec VPN. In a FortiGate<br />

dialup-client configuration, a FortiGate unit with a static IP address acts as a dialup<br />

server and a FortiGate unit having a dynamic IP address initiates a VPN tunnel with the<br />

FortiGate dialup server.<br />

The following topics are included in this section:<br />

Configuration overview<br />

Configuration overview<br />

FortiGate dialup-client configuration steps<br />

Configure the server to accept FortiGate dialup-client connections<br />

Configure the FortiGate dialup client<br />

A dialup client can be a FortiGate unit—the FortiGate dialup client typically obtains a<br />

dynamic IP address from an ISP through the Dynamic Host Configuration Protocol<br />

(DHCP) or Point-to-Point Protocol over Ethernet (PPPoE) before initiating a connection to<br />

a FortiGate dialup server.<br />

Figure 19: Example FortiGate dialup-client configuration<br />

Site_1<br />

FortiGate_1<br />

FortiGate_<br />

FG_Dialup<br />

In a dialup-client configuration, the FortiGate dialup server does not rely on a phase 1<br />

remote gateway address to establish an IPsec VPN connection with dialup clients. As<br />

long as authentication is successful and the IPsec security policy associated with the<br />

tunnel permits access, the tunnel is established.<br />

FortiOS Handbook v3: IPsec VPNs<br />

01-434-112804-20120111 133<br />

http://docs.fortinet.com/<br />

Site_2

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!