03.04.2013 Views

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

fortigate-ipsec-40-mr3

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

FortiOS Handbook<br />

Supporting IKE Mode config clients<br />

IKE Mode Config is an alternative to DHCP over IPsec. A FortiGate unit can be<br />

configured as either an IKE Mode Config server or client. This chapter contains the<br />

following sections:<br />

Automatic configuration overview<br />

IKE Mode Config overview<br />

Configuring IKE Mode Config<br />

Example: FortiGate unit as IKE Mode Config server<br />

Example: FortiGate unit as IKE Mode Config client<br />

Automatic configuration overview<br />

IKE Mode Config overview<br />

VPN configuration for remote clients is simpler if it is automated. Several protocols<br />

support automatic configuration:<br />

The Fortinet FortiClient Endpoint Security application can completely configure a VPN<br />

connection with a suitably configured FortiGate unit given only the FortiGate unit’s<br />

address. This protocol is exclusive to Fortinet. For more information, see the<br />

“FortiClient dialup-client configurations” chapter.<br />

DHCP over IPsec can assign an IP address, Domain, DNS and WINS addresses. The<br />

user must first configure IPsec parameters such as gateway address, encryption and<br />

authentication algorithms.<br />

IKE Mode Config can configure host IP address, Domain, DNS and WINS addresses.<br />

The user must first configure IPsec parameters such as gateway address, encryption<br />

and authentication algorithms. Several network equipment vendors support IKE Mode<br />

Config, which is described in the ISAKMP Configuration Method document<br />

draft-dukes-ike-mode-cfg-02.txt.<br />

This chapter describes how to configure a FortiGate unit as either an IKE Mode Config<br />

server or client.<br />

Dialup VPN clients connect to a FortiGate unit that acts as a VPN server, providing the<br />

client the necessary configuration information to establish a VPN tunnel. The<br />

configuration information typically includes a virtual IP address, netmask, and DNS server<br />

address.<br />

IKE Mode Config is available only for VPNs that are route-based, also known as<br />

interface-based. A FortiGate unit can function as either an IKE Configuration Method<br />

server or client. IKE Mode Config is configurable only in the CLI.<br />

FortiOS Handbook v3: IPsec VPNs<br />

01-434-112804-20120111 141<br />

http://docs.fortinet.com/

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!