fortigate-ipsec-40-mr3
fortigate-ipsec-40-mr3
fortigate-ipsec-40-mr3
You also want an ePaper? Increase the reach of your titles
YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.
FortiOS Handbook<br />
Supporting IKE Mode config clients<br />
IKE Mode Config is an alternative to DHCP over IPsec. A FortiGate unit can be<br />
configured as either an IKE Mode Config server or client. This chapter contains the<br />
following sections:<br />
Automatic configuration overview<br />
IKE Mode Config overview<br />
Configuring IKE Mode Config<br />
Example: FortiGate unit as IKE Mode Config server<br />
Example: FortiGate unit as IKE Mode Config client<br />
Automatic configuration overview<br />
IKE Mode Config overview<br />
VPN configuration for remote clients is simpler if it is automated. Several protocols<br />
support automatic configuration:<br />
The Fortinet FortiClient Endpoint Security application can completely configure a VPN<br />
connection with a suitably configured FortiGate unit given only the FortiGate unit’s<br />
address. This protocol is exclusive to Fortinet. For more information, see the<br />
“FortiClient dialup-client configurations” chapter.<br />
DHCP over IPsec can assign an IP address, Domain, DNS and WINS addresses. The<br />
user must first configure IPsec parameters such as gateway address, encryption and<br />
authentication algorithms.<br />
IKE Mode Config can configure host IP address, Domain, DNS and WINS addresses.<br />
The user must first configure IPsec parameters such as gateway address, encryption<br />
and authentication algorithms. Several network equipment vendors support IKE Mode<br />
Config, which is described in the ISAKMP Configuration Method document<br />
draft-dukes-ike-mode-cfg-02.txt.<br />
This chapter describes how to configure a FortiGate unit as either an IKE Mode Config<br />
server or client.<br />
Dialup VPN clients connect to a FortiGate unit that acts as a VPN server, providing the<br />
client the necessary configuration information to establish a VPN tunnel. The<br />
configuration information typically includes a virtual IP address, netmask, and DNS server<br />
address.<br />
IKE Mode Config is available only for VPNs that are route-based, also known as<br />
interface-based. A FortiGate unit can function as either an IKE Configuration Method<br />
server or client. IKE Mode Config is configurable only in the CLI.<br />
FortiOS Handbook v3: IPsec VPNs<br />
01-434-112804-20120111 141<br />
http://docs.fortinet.com/